From e52d00b53d29261e6ec5af764d56be8674392b00 Mon Sep 17 00:00:00 2001 From: research bot Date: Mon, 31 Jan 2022 20:04:12 +0000 Subject: [PATCH 1/3] updating docs and package bits [ci skip] --- .../active_setup_registry_autostart.yml | 24 +- ...d_defaultuser_and_password_in_registry.yml | 27 +- ...ound_traffic_by_firewall_rule_registry.yml | 29 +- .../allow_operation_with_consent_admin.yml | 26 +- .../disable_amsi_through_registry.yml | 24 +- .../disable_defender_antivirus_registry.yml | 25 +- ...able_defender_blockatfirstseen_feature.yml | 24 +- ...disable_defender_enhanced_notification.yml | 24 +- .../disable_defender_mpengine_registry.yml | 24 +- .../disable_defender_spynet_reporting.yml | 24 +- ...efender_submit_samples_consent_feature.yml | 24 +- .../endpoint/disable_etw_through_registry.yml | 24 +- detections/endpoint/disable_registry_tool.yml | 24 +- ...le_security_logs_using_minint_registry.yml | 23 +- .../endpoint/disable_show_hidden_files.yml | 28 +- .../disable_uac_remote_restriction.yml | 24 +- .../endpoint/disable_windows_app_hotkeys.yml | 24 +- .../disable_windows_behavior_monitoring.yml | 37 +- ...disable_windows_smartscreen_protection.yml | 23 +- .../endpoint/disabling_cmd_application.yml | 25 +- .../endpoint/disabling_controlpanel.yml | 25 +- .../endpoint/disabling_defender_services.yml | 26 +- ...isabling_folderoptions_windows_feature.yml | 25 +- .../endpoint/disabling_norun_windows_app.yml | 25 +- .../disabling_systemrestore_in_registry.yml | 27 +- .../endpoint/disabling_task_manager.yml | 25 +- .../enable_rdp_in_other_port_number.yml | 26 +- ...le_wdigest_uselogoncredential_registry.yml | 25 +- detections/endpoint/etw_registry_disabled.yml | 24 +- detections/endpoint/eventvwr_uac_bypass.yml | 25 +- .../hide_user_account_from_sign_in_screen.yml | 25 +- ...entially_malicious_code_on_commandline.yml | 86 +- .../registry_keys_used_for_persistence.yml | 39 +- ...try_keys_used_for_privilege_escalation.yml | 25 +- .../remcos_client_registry_install_entry.yml | 21 +- detections/endpoint/revil_registry_entry.yml | 24 +- ...ar_unallocated_sector_using_cipher_app.yml | 78 +- .../endpoint/ssa___fsutil_zeroing_file.yml | 3 - ..._files_and_directories_with_attrib_exe.yml | 58 +- .../start_up_during_safe_mode_boot.yml | 21 +- .../time_provider_persistence_registry.yml | 24 +- .../windows_possible_credential_dumping.yml | 16 +- ...anomalous_usage_of_account_credentials.yml | 59 +- ...___disable_defender_antivirus_registry.yml | 29 +- dist/escu/app.manifest | 2 +- dist/escu/default/analyticstories.conf | 20 +- dist/escu/default/app.conf | 4 +- dist/escu/default/collections.conf | 2 +- dist/escu/default/content-version.conf | 2 +- dist/escu/default/es_investigations.conf | 2 +- dist/escu/default/macros.conf | 10 +- dist/escu/default/savedsearches.conf | 317 +- dist/escu/default/transforms.conf | 15 +- ...lspl_unusual_commandline_detection.mlmodel | 2 + ...seen_gcp_storage_access_from_remote_ip.csv | 1 + docs/_data/navigation.yml | 2 + docs/_pages/detections.md | 5 + docs/_pages/endpoint_registry.md | 9 + docs/_playbooks/delete_detected_files.md | 5 + docs/_playbooks/log4j_investigate.md | 45 + docs/_playbooks/log4j_respond.md | 45 + .../ransomware_investigate_and_contain.md | 5 + ...detect_gcp_storage_access_from_a_new_ip.md | 4 +- ....md => 2021-01-26-revil_registry_entry.md} | 17 +- ...-anomalous_usage_of_account_credentials.md | 102 + ...-08-disable_defender_antivirus_registry.md | 103 + ...ear_unallocated_sector_using_cipher_app.md | 108 + ...g_files_and_directories_with_attrib_exe.md | 97 + ...tentially_malicious_code_on_commandline.md | 106 + ...-01-26-active_setup_registry_autostart.md} | 17 +- ...d_defaultuser_and_password_in_registry.md} | 17 +- ...ound_traffic_by_firewall_rule_registry.md} | 25 +- ...-26-allow_operation_with_consent_admin.md} | 17 +- ...22-01-26-disable_amsi_through_registry.md} | 17 +- ...26-disable_defender_antivirus_registry.md} | 17 +- ...able_defender_blockatfirstseen_feature.md} | 17 +- ...disable_defender_enhanced_notification.md} | 17 +- ...-26-disable_defender_mpengine_registry.md} | 17 +- ...1-26-disable_defender_spynet_reporting.md} | 17 +- ...efender_submit_samples_consent_feature.md} | 17 +- ...-26-registry_keys_used_for_persistence.md} | 19 +- ...try_keys_used_for_privilege_escalation.md} | 19 +- ...6-remcos_client_registry_install_entry.md} | 19 +- ...2-01-26-start_up_during_safe_mode_boot.md} | 17 +- ...-26-time_provider_persistence_registry.md} | 19 +- ...022-01-27-disable_etw_through_registry.md} | 17 +- ...md => 2022-01-27-disable_registry_tool.md} | 17 +- ...le_security_logs_using_minint_registry.md} | 18 +- ...> 2022-01-27-disable_show_hidden_files.md} | 17 +- ...2-01-27-disable_uac_remote_restriction.md} | 17 +- ...2022-01-27-disable_windows_app_hotkeys.md} | 17 +- ...27-disable_windows_behavior_monitoring.md} | 17 +- ...disable_windows_smartscreen_protection.md} | 17 +- ...> 2022-01-27-disabling_cmd_application.md} | 17 +- ...d => 2022-01-27-disabling_controlpanel.md} | 17 +- ...27-windows_possible_credential_dumping.md} | 10 +- ...2022-01-28-disabling_defender_services.md} | 17 +- ...isabling_folderoptions_windows_feature.md} | 17 +- ...2022-01-28-disabling_norun_windows_app.md} | 17 +- ...28-disabling_systemrestore_in_registry.md} | 17 +- ...d => 2022-01-28-disabling_task_manager.md} | 17 +- ...-01-28-enable_rdp_in_other_port_number.md} | 17 +- ...le_wdigest_uselogoncredential_registry.md} | 18 +- ...md => 2022-01-28-etw_registry_disabled.md} | 18 +- ...s.md => 2022-01-28-eventvwr_uac_bypass.md} | 17 +- ...-hide_user_account_from_sign-in_screen.md} | 17 +- docs/_stories/information_sabotage.md | 2 + docs/_stories/ransomware.md | 1 + .../suspicious_command-line_executions.md | 1 + .../windows_defense_evasion_tactics.md | 1 + .../windows_persistence_techniques.md | 4 +- docs/index.markdown | 4 +- docs/mitre-map/coverage.csv | 120143 ++++++++------- docs/mitre-map/coverage.json | 11370 +- 114 files changed, 69055 insertions(+), 65410 deletions(-) create mode 100644 dist/escu/lookups/__mlspl_unusual_commandline_detection.mlmodel create mode 100644 dist/escu/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv create mode 100644 docs/_pages/endpoint_registry.md rename docs/_posts/{2021-06-02-revil_registry_entry.md => 2021-01-26-revil_registry_entry.md} (74%) create mode 100644 docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md create mode 100644 docs/_posts/2021-12-08-disable_defender_antivirus_registry.md create mode 100644 docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md create mode 100644 docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md create mode 100644 docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md rename docs/_posts/{2021-09-28-active_setup_registry_autostart.md => 2022-01-26-active_setup_registry_autostart.md} (78%) rename docs/_posts/{2021-09-06-add_defaultuser_and_password_in_registry.md => 2022-01-26-add_defaultuser_and_password_in_registry.md} (73%) rename docs/_posts/{2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md => 2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md} (72%) rename docs/_posts/{2021-06-10-allow_operation_with_consent_admin.md => 2022-01-26-allow_operation_with_consent_admin.md} (73%) rename docs/_posts/{2021-06-22-disable_amsi_through_registry.md => 2022-01-26-disable_amsi_through_registry.md} (78%) rename docs/_posts/{2021-10-18-disable_defender_antivirus_registry.md => 2022-01-26-disable_defender_antivirus_registry.md} (73%) rename docs/_posts/{2021-10-18-disable_defender_blockatfirstseen_feature.md => 2022-01-26-disable_defender_blockatfirstseen_feature.md} (72%) rename docs/_posts/{2021-10-18-disable_defender_enhanced_notification.md => 2022-01-26-disable_defender_enhanced_notification.md} (72%) rename docs/_posts/{2021-10-18-disable_defender_mpengine_registry.md => 2022-01-26-disable_defender_mpengine_registry.md} (73%) rename docs/_posts/{2021-10-18-disable_defender_spynet_reporting.md => 2022-01-26-disable_defender_spynet_reporting.md} (72%) rename docs/_posts/{2021-10-18-disable_defender_submit_samples_consent_feature.md => 2022-01-26-disable_defender_submit_samples_consent_feature.md} (72%) rename docs/_posts/{2021-09-07-registry_keys_used_for_persistence.md => 2022-01-26-registry_keys_used_for_persistence.md} (59%) rename docs/_posts/{2020-11-27-registry_keys_used_for_privilege_escalation.md => 2022-01-26-registry_keys_used_for_privilege_escalation.md} (73%) rename docs/_posts/{2021-09-24-remcos_client_registry_install_entry.md => 2022-01-26-remcos_client_registry_install_entry.md} (71%) rename docs/_posts/{2021-06-10-start_up_during_safe_mode_boot.md => 2022-01-26-start_up_during_safe_mode_boot.md} (76%) rename docs/_posts/{2021-09-29-time_provider_persistence_registry.md => 2022-01-26-time_provider_persistence_registry.md} (72%) rename docs/_posts/{2021-06-22-disable_etw_through_registry.md => 2022-01-27-disable_etw_through_registry.md} (72%) rename docs/_posts/{2021-03-31-disable_registry_tool.md => 2022-01-27-disable_registry_tool.md} (78%) rename docs/_posts/{2021-10-05-disable_security_logs_using_minint_registry.md => 2022-01-27-disable_security_logs_using_minint_registry.md} (74%) rename docs/_posts/{2021-03-31-disable_show_hidden_files.md => 2022-01-27-disable_show_hidden_files.md} (75%) rename docs/_posts/{2021-09-29-disable_uac_remote_restriction.md => 2022-01-27-disable_uac_remote_restriction.md} (78%) rename docs/_posts/{2021-05-05-disable_windows_app_hotkeys.md => 2022-01-27-disable_windows_app_hotkeys.md} (73%) rename docs/_posts/{2021-03-31-disable_windows_behavior_monitoring.md => 2022-01-27-disable_windows_behavior_monitoring.md} (69%) rename docs/_posts/{2021-03-31-disable_windows_smartscreen_protection.md => 2022-01-27-disable_windows_smartscreen_protection.md} (77%) rename docs/_posts/{2021-03-31-disabling_cmd_application.md => 2022-01-27-disabling_cmd_application.md} (77%) rename docs/_posts/{2021-03-31-disabling_controlpanel.md => 2022-01-27-disabling_controlpanel.md} (76%) rename docs/_posts/{2022-01-10-windows_possible_credential_dumping.md => 2022-01-27-windows_possible_credential_dumping.md} (92%) rename docs/_posts/{2021-10-20-disabling_defender_services.md => 2022-01-28-disabling_defender_services.md} (71%) rename docs/_posts/{2021-03-31-disabling_folderoptions_windows_feature.md => 2022-01-28-disabling_folderoptions_windows_feature.md} (77%) rename docs/_posts/{2021-03-31-disabling_norun_windows_app.md => 2022-01-28-disabling_norun_windows_app.md} (78%) rename docs/_posts/{2021-03-31-disabling_systemrestore_in_registry.md => 2022-01-28-disabling_systemrestore_in_registry.md} (74%) rename docs/_posts/{2021-03-31-disabling_task_manager.md => 2022-01-28-disabling_task_manager.md} (77%) rename docs/_posts/{2021-05-19-enable_rdp_in_other_port_number.md => 2022-01-28-enable_rdp_in_other_port_number.md} (70%) rename docs/_posts/{2021-10-05-enable_wdigest_uselogoncredential_registry.md => 2022-01-28-enable_wdigest_uselogoncredential_registry.md} (78%) rename docs/_posts/{2021-10-07-etw_registry_disabled.md => 2022-01-28-etw_registry_disabled.md} (75%) rename docs/_posts/{2021-03-01-eventvwr_uac_bypass.md => 2022-01-28-eventvwr_uac_bypass.md} (81%) rename docs/_posts/{2021-05-05-hide_user_account_from_sign-in_screen.md => 2022-01-28-hide_user_account_from_sign-in_screen.md} (73%) diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index d9b7e17ba7..f35ad265fb 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -13,17 +13,19 @@ description: This analytic is to detect a suspicious modification of the active do the modification since modification of this registry is not commonly done. check the legitimacy of the file and process involve in this rules to check if it is a valid setup installer that creating or modifying this registry. -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry - where Registry.registry_value_name= "StubPath" Registry.registry_path = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `active_setup_registry_autostart_filter`' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where Registry.registry_value_name= "StubPath" Registry.registry_path = "*\\SOFTWARE\\Microsoft\\Active + Setup\\Installed Components*" by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.registry_value_data Registry.process_guid + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name + parent_process process_name process_path process proc_guid registry_path registry_value_name + registry_value_data | `active_setup_registry_autostart_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 4595e0e2b6..36c48573a3 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -12,18 +12,21 @@ description: this search is to detect a suspicious registry modification to impl continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" - AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_value_data Registry.registry_key_name - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `add_defaultuser_and_password_in_registry_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" + AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= + DefaultUserName by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.process_guid Registry.registry_value_data + Registry.registry_key_name | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `add_defaultuser_and_password_in_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 2efb621292..4252ceadb4 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -10,20 +10,21 @@ description: This analytic detects a potential suspicious modification of firewa rule registry allowing inbound traffic in specific port with public profile. This technique was identified when an adversary wants to grant remote access to a machine by allowing the traffic in a firewall rule. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" - Registry.registry_value_data = "*|Action=Allow|*" - Registry.registry_value_data = "*|Dir=In|*" - Registry.registry_value_data = "*|Profile=Public|*" - Registry.registry_value_data = "*|LPort=*" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" + Registry.registry_value_data = "*|Action=Allow|*" Registry.registry_value_data = + "*|Dir=In|*" Registry.registry_value_data = "*|Profile=Public|*" Registry.registry_value_data + = "*|LPort=*" by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `allow_inbound_traffic_by_firewall_rule_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index b17162e1ca..a557dbe759 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -11,18 +11,20 @@ description: This analytic identifies a potential privilege escalation attempt t Admin` to perform an operation that requires elevation without consent or credentials. We also found this in some attacker to gain privilege escalation to the compromise machine. -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry - where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" - Registry.registry_value_name = ConsentPromptBehaviorAdmin - Registry.registry_value_data = "0x00000000" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" + Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data + = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `allow_operation_with_consent_admin_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 15b192086a..22234c482b 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -10,17 +10,19 @@ description: this search is to identify modification in registry to disable AMSI feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_amsi_through_registry_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows + Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" by _time + span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_amsi_through_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml index 661bda6154..e40fe53195 100644 --- a/detections/endpoint/disable_defender_antivirus_registry.yml +++ b/detections/endpoint/disable_defender_antivirus_registry.yml @@ -11,18 +11,19 @@ description: This particular behavior is typically executed when an adversaries detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name = DisableAntiVirus Registry.registry_value_data = 0x00000001 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_defender_antivirus_registry_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name + = DisableAntiVirus Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest + Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_antivirus_registry_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml index 61fb400ab2..bd97d5d414 100644 --- a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml +++ b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml @@ -10,17 +10,19 @@ description: This analytic is to detect a suspicious modification of registry to windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the BlockAtFirstSeen feature where it block suspicious file first seen in the host. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_defender_blockatfirstseen_feature_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name + = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001 by _time span=1h + Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_blockatfirstseen_feature_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/detections/endpoint/disable_defender_enhanced_notification.yml b/detections/endpoint/disable_defender_enhanced_notification.yml index 3c5eafbc45..cd7a294eaa 100644 --- a/detections/endpoint/disable_defender_enhanced_notification.yml +++ b/detections/endpoint/disable_defender_enhanced_notification.yml @@ -10,17 +10,19 @@ description: This analytic is to detect a suspicious modification of registry to windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the Enhanced Notification feature wher user or admin set to show or display alerts. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path = "*Microsoft\\Windows Defender\\Reporting*" Registry.registry_value_name = DisableEnhancedNotifications Registry.registry_value_data = 0x00000001 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_defender_enhanced_notification_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path = "*Microsoft\\Windows Defender\\Reporting*" Registry.registry_value_name + = DisableEnhancedNotifications Registry.registry_value_data = 0x00000001 by _time + span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_enhanced_notification_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 diff --git a/detections/endpoint/disable_defender_mpengine_registry.yml b/detections/endpoint/disable_defender_mpengine_registry.yml index 2e16e99cff..468cb03887 100644 --- a/detections/endpoint/disable_defender_mpengine_registry.yml +++ b/detections/endpoint/disable_defender_mpengine_registry.yml @@ -11,17 +11,19 @@ description: This particular behavior is typically executed when an adversaries detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_defender_mpengine_registry_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" + Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000 + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_mpengine_registry_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/detections/endpoint/disable_defender_spynet_reporting.yml b/detections/endpoint/disable_defender_spynet_reporting.yml index 22f3fccf77..98f171623a 100644 --- a/detections/endpoint/disable_defender_spynet_reporting.yml +++ b/detections/endpoint/disable_defender_spynet_reporting.yml @@ -9,17 +9,19 @@ datamodel: description: This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the spynet reporting for its telemetry. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SpynetReporting Registry.registry_value_data = 0x00000000 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_defender_spynet_reporting_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name + = SpynetReporting Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest + Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_spynet_reporting_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml index 79f33968cd..3bc68fd9ea 100644 --- a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml +++ b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml @@ -9,17 +9,19 @@ datamodel: description: his analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the submit samples feature for further analysis.. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SubmitSamplesConsent Registry.registry_value_data = 0x00000000 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_defender_submit_samples_consent_feature_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name + = SubmitSamplesConsent Registry.registry_value_data = 0x00000000 by _time span=1h + Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_submit_samples_consent_feature_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index 92778aa40a..9c24bc8265 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -10,17 +10,19 @@ description: this search is to identify modification in registry to disable ETW feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_data = "0x00000000" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_etw_through_registry_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" + Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_etw_through_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index 2c65926b27..bdcbb8d1e1 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -11,17 +11,19 @@ description: This search identifies modification of registry to disable the rege knife in analyzing registry, malware such as RAT or trojan Spy disable this application to prevent the removal of their registry entry such as persistence, file less components and defense evasion. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_registry_tool_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" + Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_registry_tool_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disable_security_logs_using_minint_registry.yml b/detections/endpoint/disable_security_logs_using_minint_registry.yml index b66913c8cf..38e5f85a85 100644 --- a/detections/endpoint/disable_security_logs_using_minint_registry.yml +++ b/detections/endpoint/disable_security_logs_using_minint_registry.yml @@ -10,17 +10,18 @@ description: This analytic is to detect a suspicious registry modification to di security audit logs. This technique was shared by a researcher to disable Security logs of windows by adding this registry. The Windows will think it is WinPE and will not log any event to the Security Log -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry - where Registry.registry_path="*\\Control\\MiniNt\\*" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_security_logs_using_minint_registry_filter`' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where Registry.registry_path="*\\Control\\MiniNt\\*" by _time span=1h Registry.dest + Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_security_logs_using_minint_registry_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response diff --git a/detections/endpoint/disable_show_hidden_files.yml b/detections/endpoint/disable_show_hidden_files.yml index 6797c3d6c6..ced2b6bebf 100644 --- a/detections/endpoint/disable_show_hidden_files.yml +++ b/detections/endpoint/disable_show_hidden_files.yml @@ -10,19 +10,21 @@ description: The following analytic is to identify a modification in the Windows to prevent users from seeing all the files with hidden attributes. This event or techniques are known on some worm and trojan spy malware that will drop hidden files on the infected machine. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" - OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_data = "0x00000001") - OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_data = "0x00000000") - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_show_hidden_files_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" + OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" + Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" + Registry.registry_value_data = "0x00000000") by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_show_hidden_files_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml index e383fca916..06b21b3b9a 100644 --- a/detections/endpoint/disable_uac_remote_restriction.yml +++ b/detections/endpoint/disable_uac_remote_restriction.yml @@ -11,17 +11,19 @@ description: This analytic is to detect a suspicious modification of registry to attacker may modify this registry value to bypassed UAC feature of windows host. This is a good indicator that some tries to bypassed UAC to suspicious process or gain privilege escalation. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry - where Registry.registry_path="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_uac_remote_restriction_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\CurrentVersion\\Policies\\System*" + Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_uac_remote_restriction_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index a277aab0cf..389c13249b 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -11,16 +11,20 @@ description: This analytic detects a suspicious registry modification to disable used to disable certain or several Windows applications like `taskmgr.exe` and `cmd.exe`. This technique is used to impair the analyst in analyzing and removing the attacker implant in compromised systems. -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry - where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_data= "HotKey Disabled" AND Registry.registry_value_name = "Debugger" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution + Options\\*" AND Registry.registry_value_data= "HotKey Disabled" AND Registry.registry_value_name + = "Debugger" by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disable_windows_app_hotkeys_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 6ffad3e3eb..af882858ca 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -9,23 +9,26 @@ datamodel: description: This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" - OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" - OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" - OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" - OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" - OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" - OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" AND Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_windows_behavior_monitoring_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time + Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows + Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= + "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" + OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time + Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time + Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time + Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" + AND Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_windows_behavior_monitoring_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disable_windows_smartscreen_protection.yml b/detections/endpoint/disable_windows_smartscreen_protection.yml index ffd49d30b8..6f5fa6cbd7 100644 --- a/detections/endpoint/disable_windows_smartscreen_protection.yml +++ b/detections/endpoint/disable_windows_smartscreen_protection.yml @@ -11,17 +11,18 @@ description: The following search identifies a modification of registry to disab early warning system against website that might engage in phishing attack or malware distribution. This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_data= "Off" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disable_windows_smartscreen_protection_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_data= + "Off" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disable_windows_smartscreen_protection_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index 78200a7dc9..018f519f8a 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -10,17 +10,20 @@ description: this search is to identify modification in registry to disable cmd application. This technique is commonly seen in RAT, Trojan or WORM to prevent triaging or deleting there samples through cmd application which is one of the tool of analyst to traverse on directory and files. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `disabling_cmd_application_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" + Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid + Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `disabling_cmd_application_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index 10b3524ec8..6c95b48f7c 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -9,17 +9,20 @@ datamodel: description: this search is to identify registry modification to disable control panel window. This technique is commonly seen in malware to prevent their artifacts , persistence removed on the infected machine. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `disabling_controlpanel_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" + Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid + Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `disabling_controlpanel_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disabling_defender_services.yml b/detections/endpoint/disabling_defender_services.yml index 16549d8fcf..56601bec71 100644 --- a/detections/endpoint/disabling_defender_services.yml +++ b/detections/endpoint/disabling_defender_services.yml @@ -11,18 +11,20 @@ description: This particular behavior is typically executed when an adversaries detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*","*WinDefend*", "*SecurityHealthService*")) - AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `disabling_defender_services_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path + IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*","*WinDefend*", "*SecurityHealthService*")) + AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004 + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `disabling_defender_services_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index 52a6fe5569..b55293c3ce 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -11,17 +11,20 @@ description: This search is to identify registry modification to disable folder used by malware in combination if disabling show hidden files feature to hide their files and also to hide the file extension to lure the user base on file icons or fake file extensions. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `disabling_folderoptions_windows_feature_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" + Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid + Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `disabling_folderoptions_windows_feature_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index b078b3d27a..ecca959049 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -11,17 +11,20 @@ description: This search is to identify modification of registry to disable run OS user to run known application and also to execute some reg or batch script. This technique is used malware to make cleaning of its infection more harder by preventing known application run easily through run shortcut. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `disabling_norun_windows_app_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" + Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid + Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `disabling_norun_windows_app_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disabling_systemrestore_in_registry.yml b/detections/endpoint/disabling_systemrestore_in_registry.yml index bcaf33c385..bd64c090db 100644 --- a/detections/endpoint/disabling_systemrestore_in_registry.yml +++ b/detections/endpoint/disabling_systemrestore_in_registry.yml @@ -10,18 +10,21 @@ description: The following search identifies the modification of registry relate in disabling the system restore of a machine. This event or behavior are seen in some RAT malware to make the restore of the infected machine difficult and keep their infection on the box. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" - OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `disabling_systemrestore_in_registry_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" + OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" + Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid + Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `disabling_systemrestore_in_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index 728969ca87..e90cdf51f6 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -10,17 +10,20 @@ description: This search is to identifies modification of registry to disable th task manager of windows operating system. this event or technique are commonly seen in malware such as RAT, Trojan, TrojanSpy or worm to prevent the user to terminate their process. -search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry - where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_data = "0x00000001" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `disabling_task_manager_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" + Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid + Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `disabling_task_manager_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index 4ed6667386..b575508e9e 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -10,18 +10,20 @@ description: This search is to detect a modification to registry to enable rdp t a machine with different port number. This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry - where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" - Registry.registry_value_name = "PortNumber" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `enable_rdp_in_other_port_number_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal + Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber" by _time + span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `enable_rdp_in_other_port_number_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml index 5e3d9aabd2..fd7f939d40 100644 --- a/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml +++ b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml @@ -11,17 +11,20 @@ description: This analytic is to detect a suspicious registry modification to en and also by mimikatz to be able to dumpe the a plain text credential to the compromised or target host. This TTP is really a good indicator that someone wants to dump the crendential of the host so it must be a good pivot for credential dumping techniques. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry - where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" - Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" + Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data + = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `enable_wdigest_uselogoncredential_registry_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml index 62705503bf..38e560cc51 100644 --- a/detections/endpoint/etw_registry_disabled.yml +++ b/detections/endpoint/etw_registry_disabled.yml @@ -9,16 +9,20 @@ datamodel: description: This analytic is to detect a registry modification to disable ETW feature of windows. This technique is to evade EDR appliance to evade detections and hide its execution from audit logs. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry - where Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*" Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*" + Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.process_guid Registry.registry_key_name Registry.registry_value_data | + `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `etw_registry_disabled_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index aec55f5d02..b9672d1073 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -12,17 +12,20 @@ description: The following search identifies Eventvwr bypass by identifying the upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. -search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) - as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry - where Registry.registry_path="*mscfile\\shell\\open\\command\\*" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) + as registry_key_name values(Registry.registry_path) as registry_path min(_time) + as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.process_guid Registry.registry_key_name Registry.registry_value_data | + `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `eventvwr_uac_bypass_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index 1af333f19c..704af4fb7f 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -11,17 +11,20 @@ description: This analytic identifies a suspicious registry modification to hide where the adversary will create a hidden user account with Admin privileges in login screen to avoid noticing by the user that they already compromise and to persist on that said machine. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry - where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" - AND Registry.registry_value_data = "0x00000000" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows + NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data + = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `hide_user_account_from_sign_in_screen_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/potentially_malicious_code_on_commandline.yml b/detections/endpoint/potentially_malicious_code_on_commandline.yml index 379e346161..6bbeaa5f82 100644 --- a/detections/endpoint/potentially_malicious_code_on_commandline.yml +++ b/detections/endpoint/potentially_malicious_code_on_commandline.yml @@ -7,45 +7,60 @@ type: Anomaly datamodel: - Endpoint description: The following analytic uses a pretrained machine learning text classifier - to detect potentially malicious commandlines. The model identifies unusual - combinations of keywords found in samples of commandlines where adversaries executed - powershell code, primarily for C2 communication. For example, adversaries will leverage - IO capabilities such as "streamreader" and "webclient", threading capabilties such as - "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic + to detect potentially malicious commandlines. The model identifies unusual combinations + of keywords found in samples of commandlines where adversaries executed powershell + code, primarily for C2 communication. For example, adversaries will leverage IO + capabilities such as "streamreader" and "webclient", threading capabilties such + as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically - found in normal usage of the commandline. The model will output a score where all values - above zero are suspicious, anything greater than one particularly so. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime - max(_time) as lastTime from datamodel="Endpoint.Processes" by - Processes.parent_process_name Processes.process_name Processes.process - Processes.user Processes.dest | `drop_dm_object_name(Processes)` | where - len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score` | - apply unusual_commandline_detection | eval score=''predicted(unusual_cmdline_logits)'', - process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits) orig_process | - where score > 0.5 | `security_content_ctime(firstTime)` | - `security_content_ctime(lastTime)` | `potentially_malicious_code_on_commandline_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs - with the process name, parent process, and command-line executions from your endpoints. - If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. You - will also need to install the Machine Learning Toolkit version 5.3 or above to apply - the pretrained model. -known_false_positives: This model is an anomaly detector that identifies usage of APIs - and scripting constructs that are correllated with malicious activity. These APIs and - scripting constructs are part of the programming langauge and advanced scripts may - generate false positives. + found in normal usage of the commandline. The model will output a score where all + values above zero are suspicious, anything greater than one particularly so. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name + Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` | + where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score` + | apply unusual_commandline_detection | eval score=''predicted(unusual_cmdline_logits)'', + process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits) + orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `potentially_malicious_code_on_commandline_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. You will also need to install the Machine Learning Toolkit version 5.3 + or above to apply the pretrained model. +known_false_positives: This model is an anomaly detector that identifies usage of + APIs and scripting constructs that are correllated with malicious activity. These + APIs and scripting constructs are part of the programming langauge and advanced + scripts may generate false positives. references: - - https://attack.mitre.org/techniques/T1059/003/ - - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md +- https://attack.mitre.org/techniques/T1059/003/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md tags: analytic_story: - Suspicious Command-Line Executions + confidence: 20 + context: + - source:endpoint + - stage:Execution dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log + impact: 60 kill_chain_phases: - Exploitation + message: Unusual command-line execution with hallmarks of malicious activity run + by $user$ found on $dest$ with commandline $process$ mitre_attack_id: - T1059.003 + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -58,20 +73,5 @@ tags: - Processes.parent_process - Processes.user - Processes.dest - security_domain: endpoint - impact: 60 - confidence: 20 risk_score: 12 - context: - - source:endpoint - - stage:Execution - message: Unusual command-line execution with hallmarks of malicious activity run by $user$ found on $dest$ with commandline $process$ - observable: - - name: dest - type: Hostname - role: - - Victim - - name: user - type: User - role: - - Victim \ No newline at end of file + security_domain: endpoint diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 1132cc8d98..b9a9021e9c 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -8,29 +8,32 @@ datamodel: - Endpoint description: The search looks for modifications to registry keys that can be used to launch an application or service at system startup. -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* - OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* - OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* - OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* - OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* - OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution - Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" - AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* + OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* + OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* + OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* + OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows + NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) + OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security + Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" - AND Registry.registry_key_name="auto_update")) - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name - | `registry_keys_used_for_persistence_filter`' + AND Registry.registry_key_name="auto_update")) by _time span=1h Registry.dest Registry.user + Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `registry_keys_used_for_persistence_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 128a1bfc03..ef863cb47b 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -9,17 +9,20 @@ description: This search looks for modifications to registry keys that can be us to elevate privileges. The registry keys under "Image File Execution Options" are used to intercept calls to an executable and can be used to attach malicious binaries to benign system binaries. -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry - where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") - AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger) - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File + Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger) + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid Registry.registry_key_name | + `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name | `registry_keys_used_for_privilege_escalation_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/remcos_client_registry_install_entry.yml b/detections/endpoint/remcos_client_registry_install_entry.yml index 7cdeef0c97..a218e8cc62 100644 --- a/detections/endpoint/remcos_client_registry_install_entry.yml +++ b/detections/endpoint/remcos_client_registry_install_entry.yml @@ -9,16 +9,17 @@ datamodel: description: This search detects registry key license at host where Remcos RAT agent is installed. search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry - where (Registry.registry_key_name=*\\Software\\Remcos*) - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - |`remcos_client_registry_install_entry_filter`' + where (Registry.registry_key_name=*\\Software\\Remcos*) by _time span=1h Registry.dest + Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data |`remcos_client_registry_install_entry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure diff --git a/detections/endpoint/revil_registry_entry.yml b/detections/endpoint/revil_registry_entry.yml index 3a40434e33..c30db2d205 100644 --- a/detections/endpoint/revil_registry_entry.yml +++ b/detections/endpoint/revil_registry_entry.yml @@ -11,17 +11,19 @@ description: This analytic identifies suspicious modification in registry entry implant, malware and ransomware like REVIL where it keep some information like the random generated file extension it uses for all the encrypted files and ransomware notes file name in the compromised host. -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry - where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `revil_registry_entry_filter`' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" + OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") by _time + span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `revil_registry_entry_filter`' how_to_implement: to successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. diff --git a/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml index 52b81583ba..741de4fbae 100644 --- a/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml @@ -14,12 +14,12 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND like(cmd_line, "%/w:%") AND process_name="cipher.exe" - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%/w:%") AND process_name="cipher.exe" | + eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -32,39 +32,27 @@ tags: analytic_story: - Ransomware - Information Sabotage - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1070.004 - - T1070 - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 100 - # (impact * confidence)/100 - risk_score: 90 + cis20: + - CIS 14 + - CIS 16 + confidence: 100 context: - Source:Endpoint - Stage:Impact + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log + impact: 90 + kill_chain_phases: + - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors of a specific disk. + mitre_attack_id: + - T1070.004 + - T1070 + nist: + - PR.AC + - PR.IP observable: - name: user type: User @@ -82,10 +70,20 @@ tags: type: Process role: - Child Process - nist: - - PR.AC - - PR.IP - cis20: - - CIS 14 - - CIS 16 - \ No newline at end of file + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 90 + security_domain: endpoint diff --git a/detections/endpoint/ssa___fsutil_zeroing_file.yml b/detections/endpoint/ssa___fsutil_zeroing_file.yml index 921fd6fa62..cd8fde0bae 100644 --- a/detections/endpoint/ssa___fsutil_zeroing_file.yml +++ b/detections/endpoint/ssa___fsutil_zeroing_file.yml @@ -48,9 +48,6 @@ tags: deletion. mitre_attack_id: - T1070 - nist: - - PR.AC - - PR.IP nist: [] observable: - name: dest_user_id diff --git a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml index 5b392447be..e3fa20820f 100644 --- a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml @@ -15,12 +15,12 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND like(cmd_line, "%+h%") AND process_name="attrib.exe" - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%+h%") AND process_name="attrib.exe" | + eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' how_to_implement: You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be @@ -30,33 +30,32 @@ how_to_implement: You must be ingesting data that records process activity from known_false_positives: 'Some applications and users may legitimately use attrib.exe to interact with the files. ' references: -- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/attrib +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/attrib tags: analytic_story: - Windows Defense Evasion Tactics - Windows Persistence Techniques - Information Sabotage - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/attrib_hidden/security.log - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1222.001 - - T1222 - product: - - Splunk Behavioral Analytics - required_fields: - - _time - security_domain: endpoint - impact: 80 - confidence: 90 - # (impact * confidence)/100 - risk_score: 72 + cis20: + - CIS 14 + - CIS 16 + confidence: 90 context: - Source:Endpoint - Stage:Defense Evasion - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/attrib_hidden/security.log + impact: 80 + kill_chain_phases: + - Exploitation message: Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. + mitre_attack_id: + - T1222.001 + - T1222 + nist: + - PR.AC + - PR.IP observable: - name: user type: User @@ -71,10 +70,9 @@ tags: role: - Attacker - Parent Process - nist: - - PR.AC - - PR.IP - cis20: - - CIS 14 - - CIS 16 - + product: + - Splunk Behavioral Analytics + required_fields: + - _time + risk_score: 72 + security_domain: endpoint diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index 26abd617b8..1e114c7ac9 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -9,17 +9,18 @@ datamodel: description: This search is to detect a modification or registry add to the safeboot registry as an autostart mechanism. This technique was seen in some ransomware to automatically execute its code upon a safe mode boot. -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `start_up_during_safe_mode_boot_filter`' + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `start_up_during_safe_mode_boot_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index 5b4dcff038..b39e88bbc0 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -11,17 +11,19 @@ description: This analytic is to detect a suspicious modification of time provid persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry - where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" - by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid - | `drop_dm_object_name(Registry)` - |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid - | `drop_dm_object_name(Processes)` - |rename process_guid as proc_guid - | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] - | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data - | `time_provider_persistence_registry_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path + ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by _time span=1h Registry.dest + Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data + Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as + proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `time_provider_persistence_registry_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response diff --git a/detections/endpoint/windows_possible_credential_dumping.yml b/detections/endpoint/windows_possible_credential_dumping.yml index 198b71ca45..4518de4683 100644 --- a/detections/endpoint/windows_possible_credential_dumping.yml +++ b/detections/endpoint/windows_possible_credential_dumping.yml @@ -24,18 +24,18 @@ description: 'The following analytic is an enhanced version of two previous anal For example in sekurlsa module there are many ntdll exported api, like RtlCopyMemory, used to execute this module which is related to lsass dumping.' search: '`sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess IN ("0x01000", - "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", - "0x1438", "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") - | stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, - GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser | rename Computer - as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - | `windows_possible_credential_dumping_filter`' + "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438", + "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") | stats + count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess, + SourceImage, SourceProcessId, SourceUser, TargetUser | rename Computer as dest | + `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_possible_credential_dumping_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Enabling EventCode 10 TargetProcess lsass.exe is required. -known_false_positives: False positives will occur based on GrantedAccess 0x1010 and 0x1400, filter based - on source image as needed or remove them. Concern is Cobalt Strike usage of Mimikatz will generate 0x1010 initially, but later be caught. +known_false_positives: False positives will occur based on GrantedAccess 0x1010 and + 0x1400, filter based on source image as needed or remove them. Concern is Cobalt + Strike usage of Mimikatz will generate 0x1010 initially, but later be caught. references: - https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service - https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump diff --git a/detections/experimental/endpoint/ssa___anomalous_usage_of_account_credentials.yml b/detections/experimental/endpoint/ssa___anomalous_usage_of_account_credentials.yml index 8c74a30736..b0aad151f4 100644 --- a/detections/experimental/endpoint/ssa___anomalous_usage_of_account_credentials.yml +++ b/detections/experimental/endpoint/ssa___anomalous_usage_of_account_credentials.yml @@ -6,43 +6,56 @@ author: Lou Stella, Splunk type: Anomaly datamodel: - Endpoint_Processes -description: This is an anomaly generating detection looking for multiple interactive logins within a specific time period. An insider threat may attempt to steal colleagues credentials in low tech, undetectable methods, in order to gain access to additional information or to hide their own behavior. This should capture their attempted use of those credentials on a workstation. -search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), auth_type=ucast(map_get(input_event, "authentication_type"), "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), src_user=ucast(map_get(input_event, "dest_user_original_artifact"), "string", null), signature_id=ucast(map_get(input_event, "EventCode"), "string", null) | where signature_id="4624" | where auth_type="2" OR auth_type="11" | where NOT (src_user="SYSTEM") AND NOT (src_user="ANONYMOUS LOGON") | stats estdc(src_user) AS user_counter by device, span(timestamp, 600s, 300s) | where user_counter>=2 | rename window_end AS timestamp | eval start_time=window_start, end_time=timestamp, entities=mvappend(device), body=create_map(["user_counter", user_counter, "device", device]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this detection, you need to be ingesting logon events from workstations. +description: This is an anomaly generating detection looking for multiple interactive + logins within a specific time period. An insider threat may attempt to steal colleagues + credentials in low tech, undetectable methods, in order to gain access to additional + information or to hide their own behavior. This should capture their attempted use + of those credentials on a workstation. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), auth_type=ucast(map_get(input_event, "authentication_type"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), src_user=ucast(map_get(input_event, "dest_user_original_artifact"), "string", + null), signature_id=ucast(map_get(input_event, "EventCode"), "string", null) | where + signature_id="4624" | where auth_type="2" OR auth_type="11" | where NOT (src_user="SYSTEM") + AND NOT (src_user="ANONYMOUS LOGON") | stats estdc(src_user) AS user_counter by + device, span(timestamp, 600s, 300s) | where user_counter>=2 | rename window_end + AS timestamp | eval start_time=window_start, end_time=timestamp, entities=mvappend(device), + body=create_map(["user_counter", user_counter, "device", device]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this detection, you need to be ingesting + logon events from workstations. known_false_positives: Shared workstations can cause false positives references: -- https://attack.mitre.org/techniques/T1078/002/ +- https://attack.mitre.org/techniques/T1078/002/ tags: analytic_story: - Insider Threat - kill_chain_phases: - - Privilege Escalation - - Lateral Movement - mitre_attack_id: - - T1078.002 cis20: - CIS 14 - nist: - - PR.AC - - DE.AE - product: - - Splunk Behavioral Analytics - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_login/windows-security.log - required_fields: - - _time - security_domain: access - impact: 20 confidence: 30 - risk_score: 6 context: - Source:Endpoint - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_login/windows-security.log + impact: 20 + kill_chain_phases: + - Privilege Escalation + - Lateral Movement message: Multiple interactive logins detected on $device$ - risk_severity: low + mitre_attack_id: + - T1078.002 + nist: + - PR.AC + - DE.AE observable: - name: device type: Hostname role: - Victim - + product: + - Splunk Behavioral Analytics + required_fields: + - _time + risk_score: 6 + risk_severity: low + security_domain: access diff --git a/detections/experimental/ssa___disable_defender_antivirus_registry.yml b/detections/experimental/ssa___disable_defender_antivirus_registry.yml index d63cd977fa..48e10acfc3 100644 --- a/detections/experimental/ssa___disable_defender_antivirus_registry.yml +++ b/detections/experimental/ssa___disable_defender_antivirus_registry.yml @@ -11,23 +11,18 @@ description: This particular behavior is typically executed when an adversaries detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. -search: '| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event,"_time"), - "string", null)), registry_path=lower(ucast(map_get(input_event, "registry_path"), "string", - null)), registry_key_name=lower(ucast(map_get(input_event, "registry_key_name"), "string", - null)), registry_value_data=ucast(map_get(input_event, "registry_value_data"), "string", null), - process_guid=ucast(map_get(input_event, "process_guid"), "string", - null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where like(registry_path, "%\\Policies\\Microsoft\\Windows Defender%") - AND registry_key_name="DisableAntiVirus" AND registry_value_data="(0x00000001)" -| eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map( - [ "event_id", event_id, "registry_path", registry_path, "registry_key_name", - registry_key_name, "process_guid", process_guid,"registry_value_data",registry_value_data]) -| into write_ssa_detected_events();' +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), + "string", null)), registry_path=lower(ucast(map_get(input_event, "registry_path"), + "string", null)), registry_key_name=lower(ucast(map_get(input_event, "registry_key_name"), + "string", null)), registry_value_data=ucast(map_get(input_event, "registry_value_data"), + "string", null), process_guid=ucast(map_get(input_event, "process_guid"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + like(registry_path, "%\\Policies\\Microsoft\\Windows Defender%") AND registry_key_name="DisableAntiVirus" + AND registry_value_data="(0x00000001)" | eval start_time=timestamp, end_time=timestamp, + entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, + "dest_device_id"), "string", null)), body=create_map( [ "event_id", event_id, "registry_path", + registry_path, "registry_key_name", registry_key_name, "process_guid", process_guid,"registry_value_data",registry_value_data]) + | into write_ssa_detected_events();' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/dist/escu/app.manifest b/dist/escu/app.manifest index ec0d2be71a..8aedf9fc7f 100644 --- a/dist/escu/app.manifest +++ b/dist/escu/app.manifest @@ -5,7 +5,7 @@ "id": { "group": null, "name": "DA-ESS-ContentUpdate", - "version": "3.34.0" + "version": "3.34.1" }, "author": [ { diff --git a/dist/escu/default/analyticstories.conf b/dist/escu/default/analyticstories.conf index fe16337f66..c469a5878e 100644 --- a/dist/escu/default/analyticstories.conf +++ b/dist/escu/default/analyticstories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-01-26T22:49:42 UTC +# On Date: 2022-01-31T19:58:16 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -625,7 +625,7 @@ references = ["https://mbechler.github.io/2021/12/10/PSA_Log4Shell_JNDI_Injectio maintainers = [{"company": "no", "email": "-", "name": "Jose Hernandez"}] spec_version = 3 searches = ["ESCU - Any Powershell DownloadFile - Rule", "ESCU - CMD Carry Out String Command Parameter - Rule", "ESCU - Curl Download and Bash Execution - Rule", "ESCU - Detect Outbound LDAP Traffic - Rule", "ESCU - Hunting for Log4Shell - Rule", "ESCU - Java Class File download by Java User Agent - Rule", "ESCU - Linux Java Spawning Shell - Rule", "ESCU - Log4Shell JNDI Payload Injection Attempt - Rule", "ESCU - Log4Shell JNDI Payload Injection with Outbound Connection - Rule", "ESCU - Outbound Network Connection from Java Using Default Ports - Rule", "ESCU - PowerShell - Connect To Internet With Hidden Window - Rule", "ESCU - Wget Download and Bash Execution - Rule", "ESCU - Windows Java Spawning Shells - Rule"] -description = Log4Shell or CVE-2021-44228 is a Remote Code Execution (RCE) vulnerability in the Apache Log4j library, a widely used and ubiquitous logging framework for Java. The vulnerability allows an attacker who can control log messages to execute arbitrary code loaded from attacker-controlled servers and we anticipate that most apps using the Log4j library will meet this condition. /n**SOAR:** The following Splunk SOAR playbooks can be used in the response to this story's analytics: 'Log4j Respond', 'Log4j Splunk Investigation', 'Log4j Investigate' +description = Log4Shell or CVE-2021-44228 is a Remote Code Execution (RCE) vulnerability in the Apache Log4j library, a widely used and ubiquitous logging framework for Java. The vulnerability allows an attacker who can control log messages to execute arbitrary code loaded from attacker-controlled servers and we anticipate that most apps using the Log4j library will meet this condition. /n**SOAR:** The following Splunk SOAR playbooks can be used in the response to this story's analytics: 'Log4j Investigate', 'Log4j Splunk Investigation', 'Log4j Respond' narrative = In late November 2021, Chen Zhaojun of Alibaba identified a remote code execution vulnerability. Previous work was seen in a 2016 Blackhat talk by Alvaro Munoz and Oleksandr Mirosh called ["A Journey from JNDI/LDAP Manipulation to Remote Code Execution Dream Land"](https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf). Reported under the CVE ID : CVE-2021-44228, released to the public on December 10, 2021. The vulnerability is exploited through improper deserialization of user input passed into the framework. It permits remote code execution and it can allow an attacker to leak sensitive data, such as environment variables, or execute malicious software on the target system. [analytic_story://Malicious PowerShell] @@ -1072,7 +1072,7 @@ version = 2 references = ["https://attack.mitre.org/wiki/Technique/T1059", "https://www.microsoft.com/en-us/wdsi/threats/macro-malware", "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get DomainUser with PowerShell Script Block - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"] +searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get DomainUser with PowerShell Script Block - Rule", "ESCU - Potentially malicious code on commandline - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"] description = Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems. narrative = The ability to execute arbitrary commands via the Windows CLI is a primary goal for the adversary. With access to the shell, an attacker can easily run scripts and interact with the target system. Often, attackers may only have limited access to the shell or may obtain access in unusual ways. In addition, malware may execute and interact with the CLI in ways that would be considered unusual and inconsistent with typical user activity. This provides defenders with opportunities to identify suspicious use and investigate, as appropriate. This Analytic Story contains various searches to help identify this suspicious activity, as well as others to aid you in deeper investigation. @@ -6876,6 +6876,16 @@ annotations = {"kill_chain_phases": ["Lateral Movement", "Malicious PowerShell"] known_false_positives = Legitimate applications may spawn PowerShell as a child process of the the identified processes. Filter as needed. providing_technologies = [] +[savedsearch://ESCU - Potentially malicious code on commandline - Rule] +type = detection +asset_type = +confidence = medium +explanation = The following analytic uses a pretrained machine learning text classifier to detect potentially malicious commandlines. The model identifies unusual combinations of keywords found in samples of commandlines where adversaries executed powershell code, primarily for C2 communication. For example, adversaries will leverage IO capabilities such as "streamreader" and "webclient", threading capabilties such as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically found in normal usage of the commandline. The model will output a score where all values above zero are suspicious, anything greater than one particularly so. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. You will also need to install the Machine Learning Toolkit version 5.3 or above to apply the pretrained model. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003"]} +known_false_positives = This model is an anomaly detector that identifies usage of APIs and scripting constructs that are correllated with malicious activity. These APIs and scripting constructs are part of the programming langauge and advanced scripts may generate false positives. +providing_technologies = [] + [savedsearch://ESCU - PowerShell - Connect To Internet With Hidden Window - Rule] type = detection asset_type = Endpoint @@ -8699,7 +8709,7 @@ providing_technologies = [] type = detection asset_type = confidence = medium -explanation = This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. +explanation = This analytic is to detect a suspicious modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.003", "T1547"]} known_false_positives = unknown @@ -9366,7 +9376,7 @@ dbgcore.dll or dbghelp.dll are two core Windows debug DLLs that have minidump f The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll. For example in sekurlsa module there are many ntdll exported api, like RtlCopyMemory, used to execute this module which is related to lsass dumping. how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Enabling EventCode 10 TargetProcess lsass.exe is required. annotations = {"kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1003.001", "T1003"], "nist": ["DE.AE", "DE.CM"]} -known_false_positives = False positives will occur based on GrantedAccess, filter based on source image as needed. +known_false_positives = False positives will occur based on GrantedAccess 0x1010 and 0x1400, filter based on source image as needed or remove them. Concern is Cobalt Strike usage of Mimikatz will generate 0x1010 initially, but later be caught. providing_technologies = [] [savedsearch://ESCU - Windows Raccine Scheduled Task Deletion - Rule] diff --git a/dist/escu/default/app.conf b/dist/escu/default/app.conf index bf5cb4c18d..5dc0ab8511 100644 --- a/dist/escu/default/app.conf +++ b/dist/escu/default/app.conf @@ -4,7 +4,7 @@ is_configured = false state = enabled state_change_requires_restart = false -build = 4621 +build = 4768 [triggers] reload.analytic_stories = simple @@ -20,7 +20,7 @@ reload.es_investigations = simple [launcher] author = Splunk -version = 3.34.0 +version = 3.34.1 description = Explore the Analytic Stories included with ES Content Updates. [ui] diff --git a/dist/escu/default/collections.conf b/dist/escu/default/collections.conf index 3c7c88fdbf..bcef063a65 100644 --- a/dist/escu/default/collections.conf +++ b/dist/escu/default/collections.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-01-26T22:49:42 UTC +# On Date: 2022-01-31T19:58:16 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/content-version.conf b/dist/escu/default/content-version.conf index f5b1644a4d..856553a3fb 100644 --- a/dist/escu/default/content-version.conf +++ b/dist/escu/default/content-version.conf @@ -1,2 +1,2 @@ [content-version] -version = 3.34.0 +version = 3.34.1 diff --git a/dist/escu/default/es_investigations.conf b/dist/escu/default/es_investigations.conf index 6d549aebe6..3760d30279 100644 --- a/dist/escu/default/es_investigations.conf +++ b/dist/escu/default/es_investigations.conf @@ -337,7 +337,7 @@ panels = ["panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_log4shell_cve_2021_44228] label = Log4Shell CVE-2021-44228 -description = Log4Shell or CVE-2021-44228 is a Remote Code Execution (RCE) vulnerability in the Apache Log4j library, a widely used and ubiquitous logging framework for Java. The vulnerability allows an attacker who can control log messages to execute arbitrary code loaded from attacker-controlled servers and we anticipate that most apps using the Log4j library will meet this condition. /n**SOAR:** The following Splunk SOAR playbooks can be used in the response to this story's analytics: 'Log4j Respond', 'Log4j Splunk Investigation', 'Log4j Investigate' +description = Log4Shell or CVE-2021-44228 is a Remote Code Execution (RCE) vulnerability in the Apache Log4j library, a widely used and ubiquitous logging framework for Java. The vulnerability allows an attacker who can control log messages to execute arbitrary code loaded from attacker-controlled servers and we anticipate that most apps using the Log4j library will meet this condition. /n**SOAR:** The following Splunk SOAR playbooks can be used in the response to this story's analytics: 'Log4j Investigate', 'Log4j Splunk Investigation', 'Log4j Respond' disabled = 0 panels = ["panel://workbench_panel_get_notable_history___response_task"] diff --git a/dist/escu/default/macros.conf b/dist/escu/default/macros.conf index 54a860e3f5..a3be0c7df6 100644 --- a/dist/escu/default/macros.conf +++ b/dist/escu/default/macros.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-01-26T22:49:42 UTC +# On Date: 2022-01-31T19:58:16 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -210,6 +210,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet definition = eventtype="osquery-process" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. +[potentially_malicious_code_on_cmdline_tokenize_score] +definition = eval orig_process=process, process=replace(lower(process), "`", "") | makemv tokenizer="([\w\d\-]+)" process | eval unusual_cmdline_feature_for=if(match(process, "^for$"), mvcount(mvfilter(match(process, "^for$"))), 0), unusual_cmdline_feature_netsh=if(match(process, "^netsh$"), mvcount(mvfilter(match(process, "^netsh$"))), 0), unusual_cmdline_feature_readbytes=if(match(process, "^readbytes$"), mvcount(mvfilter(match(process, "^readbytes$"))), 0), unusual_cmdline_feature_set=if(match(process, "^set$"), mvcount(mvfilter(match(process, "^set$"))), 0), unusual_cmdline_feature_unrestricted=if(match(process, "^unrestricted$"), mvcount(mvfilter(match(process, "^unrestricted$"))), 0), unusual_cmdline_feature_winstations=if(match(process, "^winstations$"), mvcount(mvfilter(match(process, "^winstations$"))), 0), unusual_cmdline_feature_-value=if(match(process, "^-value$"), mvcount(mvfilter(match(process, "^-value$"))), 0), unusual_cmdline_feature_compression=if(match(process, "^compression$"), mvcount(mvfilter(match(process, "^compression$"))), 0), unusual_cmdline_feature_server=if(match(process, "^server$"), mvcount(mvfilter(match(process, "^server$"))), 0), unusual_cmdline_feature_set-mppreference=if(match(process, "^set-mppreference$"), mvcount(mvfilter(match(process, "^set-mppreference$"))), 0), unusual_cmdline_feature_terminal=if(match(process, "^terminal$"), mvcount(mvfilter(match(process, "^terminal$"))), 0), unusual_cmdline_feature_-name=if(match(process, "^-name$"), mvcount(mvfilter(match(process, "^-name$"))), 0), unusual_cmdline_feature_catch=if(match(process, "^catch$"), mvcount(mvfilter(match(process, "^catch$"))), 0), unusual_cmdline_feature_get-wmiobject=if(match(process, "^get-wmiobject$"), mvcount(mvfilter(match(process, "^get-wmiobject$"))), 0), unusual_cmdline_feature_hklm=if(match(process, "^hklm$"), mvcount(mvfilter(match(process, "^hklm$"))), 0), unusual_cmdline_feature_streamreader=if(match(process, "^streamreader$"), mvcount(mvfilter(match(process, "^streamreader$"))), 0), unusual_cmdline_feature_system32=if(match(process, "^system32$"), mvcount(mvfilter(match(process, "^system32$"))), 0), unusual_cmdline_feature_username=if(match(process, "^username$"), mvcount(mvfilter(match(process, "^username$"))), 0), unusual_cmdline_feature_webrequest=if(match(process, "^webrequest$"), mvcount(mvfilter(match(process, "^webrequest$"))), 0), unusual_cmdline_feature_count=if(match(process, "^count$"), mvcount(mvfilter(match(process, "^count$"))), 0), unusual_cmdline_feature_webclient=if(match(process, "^webclient$"), mvcount(mvfilter(match(process, "^webclient$"))), 0), unusual_cmdline_feature_writeallbytes=if(match(process, "^writeallbytes$"), mvcount(mvfilter(match(process, "^writeallbytes$"))), 0), unusual_cmdline_feature_convert=if(match(process, "^convert$"), mvcount(mvfilter(match(process, "^convert$"))), 0), unusual_cmdline_feature_create=if(match(process, "^create$"), mvcount(mvfilter(match(process, "^create$"))), 0), unusual_cmdline_feature_function=if(match(process, "^function$"), mvcount(mvfilter(match(process, "^function$"))), 0), unusual_cmdline_feature_net=if(match(process, "^net$"), mvcount(mvfilter(match(process, "^net$"))), 0), unusual_cmdline_feature_com=if(match(process, "^com$"), mvcount(mvfilter(match(process, "^com$"))), 0), unusual_cmdline_feature_http=if(match(process, "^http$"), mvcount(mvfilter(match(process, "^http$"))), 0), unusual_cmdline_feature_io=if(match(process, "^io$"), mvcount(mvfilter(match(process, "^io$"))), 0), unusual_cmdline_feature_system=if(match(process, "^system$"), mvcount(mvfilter(match(process, "^system$"))), 0), unusual_cmdline_feature_new-object=if(match(process, "^new-object$"), mvcount(mvfilter(match(process, "^new-object$"))), 0), unusual_cmdline_feature_if=if(match(process, "^if$"), mvcount(mvfilter(match(process, "^if$"))), 0), unusual_cmdline_feature_threading=if(match(process, "^threading$"), mvcount(mvfilter(match(process, "^threading$"))), 0), unusual_cmdline_feature_mutex=if(match(process, "^mutex$"), mvcount(mvfilter(match(process, "^mutex$"))), 0), unusual_cmdline_feature_cryptography=if(match(process, "^cryptography$"), mvcount(mvfilter(match(process, "^cryptography$"))), 0), unusual_cmdline_feature_computehash=if(match(process, "^computehash$"), mvcount(mvfilter(match(process, "^computehash$"))), 0) +description = Performs the tokenization and application of the malicious commandline classifier + [powershell] definition = (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational") description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. @@ -2951,6 +2955,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[potentially_malicious_code_on_commandline_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [powershell___connect_to_internet_with_hidden_window_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. diff --git a/dist/escu/default/savedsearches.conf b/dist/escu/default/savedsearches.conf index bce0ce9138..f4fd97b75b 100644 --- a/dist/escu/default/savedsearches.conf +++ b/dist/escu/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-01-26T22:49:42 UTC +# On Date: 2022-01-31T19:58:15 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -1611,8 +1611,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic is to detect a suspicious modification of the active setup registry for persistence and privilege escalation. This technique was seen in several malware (poisonIvy), adware and APT to gain persistence to the compromised machine upon boot up. This TTP is a good indicator to further check the process id that do the modification since modification of this registry is not commonly done. check the legitimacy of the file and process involve in this rules to check if it is a valid setup installer that creating or modifying this registry. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = Active setup installer may add or modify this registry. -action.escu.creation_date = 2021-09-28 -action.escu.modification_date = 2021-09-28 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Active Setup Registry Autostart - Rule action.escu.search_type = detection @@ -1645,7 +1645,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_value_name = "StubPath" Registry.registry_key_name = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `active_setup_registry_autostart_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_value_name= "StubPath" Registry.registry_path = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `active_setup_registry_autostart_filter` [ESCU - Add DefaultUser And Password In Registry - Rule] action.escu = 0 @@ -1656,8 +1656,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-09-06 -action.escu.modification_date = 2021-09-06 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Add DefaultUser And Password In Registry - Rule action.escu.search_type = detection @@ -1676,7 +1676,7 @@ action.correlationsearch.label = ESCU - Add DefaultUser And Password In Registry action.correlationsearch.annotations = {"analytic_story": ["BlackMatter Ransomware"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Credential Access"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1552.002", "T1552"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. action.notable.param.rule_title = Add DefaultUser And Password In Registry action.notable.param.security_domain = endpoint @@ -1690,7 +1690,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `add_defaultuser_and_password_in_registry_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_value_data Registry.registry_key_name | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `add_defaultuser_and_password_in_registry_filter` [ESCU - Add or Set Windows Defender Exclusion - Rule] action.escu = 0 @@ -1831,8 +1831,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. This technique was identified when an adversary wants to grant remote access to a machine by allowing the traffic in a firewall rule. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered. -action.escu.creation_date = 2021-05-26 -action.escu.modification_date = 2021-05-26 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule action.escu.search_type = detection @@ -1865,7 +1865,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_name = "*|Action=Allow|*" Registry.registry_value_name = "*|Dir=In|*" Registry.registry_value_name = "*|Profile=Public|*" Registry.registry_value_name = "*|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `allow_inbound_traffic_by_firewall_rule_registry_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_data = "*|Action=Allow|*" Registry.registry_value_data = "*|Dir=In|*" Registry.registry_value_data = "*|Profile=Public|*" Registry.registry_value_data = "*|LPort=*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `allow_inbound_traffic_by_firewall_rule_registry_filter` [ESCU - Allow Inbound Traffic In Firewall Rule - Rule] action.escu = 0 @@ -1961,8 +1961,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic identifies a potential privilege escalation attempt to perform malicious task. This registry modification is designed to allow the `Consent Admin` to perform an operation that requires elevation without consent or credentials. We also found this in some attacker to gain privilege escalation to the compromise machine. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-06-10 -action.escu.modification_date = 2021-06-10 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Allow Operation with Consent Admin - Rule action.escu.search_type = detection @@ -1981,7 +1981,7 @@ action.correlationsearch.label = ESCU - Allow Operation with Consent Admin - Rul action.correlationsearch.annotations = {"analytic_story": ["Ransomware"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Privilege Escalation"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = This analytic identifies a potential privilege escalation attempt to perform malicious task. This registry modification is designed to allow the `Consent Admin` to perform an operation that requires elevation without consent or credentials. We also found this in some attacker to gain privilege escalation to the compromise machine. action.notable.param.rule_title = Allow Operation with Consent Admin action.notable.param.security_domain = endpoint @@ -1995,7 +1995,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `allow_operation_with_consent_admin_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `allow_operation_with_consent_admin_filter` [ESCU - Amazon EKS Kubernetes Pod scan detection - Rule] action.escu = 0 @@ -6227,7 +6227,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `google_gcp_pubsub_message` | multikv | rename sc_status_ as status | rename cs_object_ as bucket_name | rename c_ip_ as remote_ip | rename cs_uri_ as request_uri | rename cs_method_ as operation | search status="\"200\"" | stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip operation request_uri | table firstTime, lastTime, bucket_name, remote_ip, operation, request_uri | inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip.csv | stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip operation request_uri | outputlookup previously_seen_gcp_storage_access_from_remote_ip.csv | eval newIP=if(firstTime >= relative_time(now(),"-70m@m"), 1, 0) | where newIP=1 | eval first_time=strftime(firstTime,"%m/%d/%y %H:%M:%S") | eval last_time=strftime(lastTime,"%m/%d/%y %H:%M:%S") | table first_time last_time bucket_name remote_ip operation request_uri | `detect_gcp_storage_access_from_a_new_ip_filter` +search = `google_gcp_pubsub_message` | multikv | rename sc_status_ as status | rename cs_object_ as bucket_name | rename c_ip_ as remote_ip | rename cs_uri_ as request_uri | rename cs_method_ as operation | search status="\"200\"" | stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip operation request_uri | table firstTime, lastTime, bucket_name, remote_ip, operation, request_uri | inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip | stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip operation request_uri | outputlookup previously_seen_gcp_storage_access_from_remote_ip | eval newIP=if(firstTime >= relative_time(now(),"-70m@m"), 1, 0) | where newIP=1 | eval first_time=strftime(firstTime,"%m/%d/%y %H:%M:%S") | eval last_time=strftime(lastTime,"%m/%d/%y %H:%M:%S") | table first_time last_time bucket_name remote_ip operation request_uri | `detect_gcp_storage_access_from_a_new_ip_filter` [ESCU - Detect HTML Help Renamed - Rule] action.escu = 0 @@ -9461,8 +9461,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = this search is to identify modification in registry to disable AMSI windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = network operator may disable this feature of windows but not so common. -action.escu.creation_date = 2021-06-22 -action.escu.modification_date = 2021-06-22 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable AMSI Through Registry - Rule action.escu.search_type = detection @@ -9477,7 +9477,7 @@ action.correlationsearch.label = ESCU - Disable AMSI Through Registry - Rule action.correlationsearch.annotations = {"analytic_story": ["Ransomware"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = this search is to identify modification in registry to disable AMSI windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. action.notable.param.rule_title = Disable AMSI Through Registry action.notable.param.security_domain = endpoint @@ -9491,7 +9491,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_amsi_through_registry_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_amsi_through_registry_filter` [ESCU - Disable Defender AntiVirus Registry - Rule] action.escu = 0 @@ -9502,8 +9502,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = admin or user may choose to disable windows defender product -action.escu.creation_date = 2021-10-18 -action.escu.modification_date = 2021-10-18 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Defender AntiVirus Registry - Rule action.escu.search_type = detection @@ -9536,7 +9536,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name = DisableAntiVirus Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_defender_antivirus_registry_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name = DisableAntiVirus Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_antivirus_registry_filter` [ESCU - Disable Defender BlockAtFirstSeen Feature - Rule] action.escu = 0 @@ -9547,8 +9547,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the BlockAtFirstSeen feature where it block suspicious file first seen in the host. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = admin or user may choose to disable windows defender product -action.escu.creation_date = 2021-10-18 -action.escu.modification_date = 2021-10-18 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Defender BlockAtFirstSeen Feature - Rule action.escu.search_type = detection @@ -9581,7 +9581,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_defender_blockatfirstseen_feature_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_blockatfirstseen_feature_filter` [ESCU - Disable Defender Enhanced Notification - Rule] action.escu = 0 @@ -9592,8 +9592,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the Enhanced Notification feature wher user or admin set to show or display alerts. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = user may choose to disable windows defender AV -action.escu.creation_date = 2021-10-18 -action.escu.modification_date = 2021-10-18 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Defender Enhanced Notification - Rule action.escu.search_type = detection @@ -9626,7 +9626,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*Microsoft\\Windows Defender\\Reporting*" Registry.registry_value_name = DisableEnhancedNotifications Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_defender_enhanced_notification_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*Microsoft\\Windows Defender\\Reporting*" Registry.registry_value_name = DisableEnhancedNotifications Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_enhanced_notification_filter` [ESCU - Disable Defender MpEngine Registry - Rule] action.escu = 0 @@ -9637,8 +9637,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = admin or user may choose to disable windows defender product -action.escu.creation_date = 2021-10-18 -action.escu.modification_date = 2021-10-18 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Defender MpEngine Registry - Rule action.escu.search_type = detection @@ -9671,7 +9671,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_defender_mpengine_registry_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_mpengine_registry_filter` [ESCU - Disable Defender Spynet Reporting - Rule] action.escu = 0 @@ -9682,8 +9682,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the spynet reporting for its telemetry. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = admin or user may choose to disable windows defender product -action.escu.creation_date = 2021-10-18 -action.escu.modification_date = 2021-10-18 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Defender Spynet Reporting - Rule action.escu.search_type = detection @@ -9716,7 +9716,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SpynetReporting Registry.registry_value_data = 0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_defender_spynet_reporting_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SpynetReporting Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_spynet_reporting_filter` [ESCU - Disable Defender Submit Samples Consent Feature - Rule] action.escu = 0 @@ -9727,8 +9727,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = his analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the submit samples feature for further analysis.. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = admin or user may choose to disable windows defender product -action.escu.creation_date = 2021-10-18 -action.escu.modification_date = 2021-10-18 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Defender Submit Samples Consent Feature - Rule action.escu.search_type = detection @@ -9761,7 +9761,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SubmitSamplesConsent Registry.registry_value_data = 0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_defender_submit_samples_consent_feature_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SubmitSamplesConsent Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_submit_samples_consent_feature_filter` [ESCU - Disable ETW Through Registry - Rule] action.escu = 0 @@ -9772,8 +9772,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = this search is to identify modification in registry to disable ETW windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = network operator may disable this feature of windows but not so common. -action.escu.creation_date = 2021-06-22 -action.escu.modification_date = 2021-06-22 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable ETW Through Registry - Rule action.escu.search_type = detection @@ -9788,7 +9788,7 @@ action.correlationsearch.label = ESCU - Disable ETW Through Registry - Rule action.correlationsearch.annotations = {"analytic_story": ["Ransomware"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = this search is to identify modification in registry to disable ETW windows feature to evade detections. This technique was seen in several ransomware, RAT and even APT to impaire defenses of the compromise machine and to be able to execute payload with minimal alert as much as possible. action.notable.param.rule_title = Disable ETW Through Registry action.notable.param.security_domain = endpoint @@ -9802,7 +9802,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_etw_through_registry_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_etw_through_registry_filter` [ESCU - Disable Logs Using WevtUtil - Rule] action.escu = 0 @@ -9858,8 +9858,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This search identifies modification of registry to disable the regedit or registry tools of the windows operating system. Since registry tool is a swiss knife in analyzing registry, malware such as RAT or trojan Spy disable this application to prevent the removal of their registry entry such as persistence, file less components and defense evasion. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin may disable this application for non technical user. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Registry Tool - Rule action.escu.search_type = detection @@ -9878,7 +9878,7 @@ action.correlationsearch.label = ESCU - Disable Registry Tool - Rule action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 40, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = This search identifies modification of registry to disable the regedit or registry tools of the windows operating system. Since registry tool is a swiss knife in analyzing registry, malware such as RAT or trojan Spy disable this application to prevent the removal of their registry entry such as persistence, file less components and defense evasion. action.notable.param.rule_title = Disable Registry Tool action.notable.param.security_domain = endpoint @@ -9892,7 +9892,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_registry_tool_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_registry_tool_filter` [ESCU - Disable Schedule Task - Rule] action.escu = 0 @@ -9948,8 +9948,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic is to detect a suspicious registry modification to disable security audit logs. This technique was shared by a researcher to disable Security logs of windows by adding this registry. The Windows will think it is WinPE and will not log any event to the Security Log action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = Unknown. -action.escu.creation_date = 2021-10-05 -action.escu.modification_date = 2021-10-05 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Security Logs Using MiniNt Registry - Rule action.escu.search_type = detection @@ -9982,7 +9982,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_security_logs_using_minint_registry_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_security_logs_using_minint_registry_filter` [ESCU - Disable Show Hidden Files - Rule] action.escu = 0 @@ -9993,8 +9993,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = The following analytic is to identify a modification in the Windows registry to prevent users from seeing all the files with hidden attributes. This event or techniques are known on some worm and trojan spy malware that will drop hidden files on the infected machine. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Show Hidden Files - Rule action.escu.search_type = detection @@ -10013,7 +10013,7 @@ action.correlationsearch.label = ESCU - Disable Show Hidden Files - Rule action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 40, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1564.001", "T1562.001", "T1564", "T1562"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = The following analytic is to identify a modification in the Windows registry to prevent users from seeing all the files with hidden attributes. This event or techniques are known on some worm and trojan spy malware that will drop hidden files on the infected machine. action.notable.param.rule_title = Disable Show Hidden Files action.notable.param.security_domain = endpoint @@ -10027,7 +10027,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_data = "0x00000000") by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_show_hidden_files_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_data = "0x00000000") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_show_hidden_files_filter` [ESCU - Disable UAC Remote Restriction - Rule] action.escu = 0 @@ -10038,8 +10038,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic is to detect a suspicious modification of registry to disable UAC remote restriction. This technique was well documented in Microsoft page where attacker may modify this registry value to bypassed UAC feature of windows host. This is a good indicator that some tries to bypassed UAC to suspicious process or gain privilege escalation. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = admin may set this policy for non-critical machine. -action.escu.creation_date = 2021-09-29 -action.escu.modification_date = 2021-09-29 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable UAC Remote Restriction - Rule action.escu.search_type = detection @@ -10072,7 +10072,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `disable_uac_remote_restriction_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_uac_remote_restriction_filter` [ESCU - Disable Windows App Hotkeys - Rule] action.escu = 0 @@ -10083,8 +10083,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic detects a suspicious registry modification to disable Windows hotkey (shortcut keys) for native Windows applications. This technique is commonly used to disable certain or several Windows applications like `taskmgr.exe` and `cmd.exe`. This technique is used to impair the analyst in analyzing and removing the attacker implant in compromised systems. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-05-05 -action.escu.modification_date = 2021-05-05 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Windows App Hotkeys - Rule action.escu.search_type = detection @@ -10117,7 +10117,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_name = "HotKey Disabled" AND Registry.registry_key_name = "Debugger" by Registry.dest Registry.user Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `disable_windows_app_hotkeys_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_data= "HotKey Disabled" AND Registry.registry_value_name = "Debugger" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disable_windows_app_hotkeys_filter` [ESCU - Disable Windows Behavior Monitoring - Rule] action.escu = 0 @@ -10128,8 +10128,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin or user may choose to disable this windows features. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Windows Behavior Monitoring - Rule action.escu.search_type = detection @@ -10148,7 +10148,7 @@ action.correlationsearch.label = ESCU - Disable Windows Behavior Monitoring - Ru action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics", "Ransomware", "Revil Ransomware"], "confidence": 100, "context": [{"Source": "Endpoint"}, {"Stage": "Defense Evasion"}], "impact": 40, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = This search is to identifies a modification in registry to disable the windows denfender real time behavior monitoring. This event or technique is commonly seen in RAT, bot, or Trojan to disable AV to evade detections. action.notable.param.rule_title = Disable Windows Behavior Monitoring action.notable.param.security_domain = endpoint @@ -10162,7 +10162,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_windows_behavior_monitoring_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" AND Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_windows_behavior_monitoring_filter` [ESCU - Disable Windows SmartScreen Protection - Rule] action.escu = 0 @@ -10173,8 +10173,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = The following search identifies a modification of registry to disable the smartscreen protection of windows machine. This is windows feature provide an early warning system against website that might engage in phishing attack or malware distribution. This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin or user may choose to disable this windows features. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disable Windows SmartScreen Protection - Rule action.escu.search_type = detection @@ -10193,7 +10193,7 @@ action.correlationsearch.label = ESCU - Disable Windows SmartScreen Protection - action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = The following search identifies a modification of registry to disable the smartscreen protection of windows machine. This is windows feature provide an early warning system against website that might engage in phishing attack or malware distribution. This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload. action.notable.param.rule_title = Disable Windows SmartScreen Protection action.notable.param.security_domain = endpoint @@ -10207,7 +10207,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_name = "Off" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_windows_smartscreen_protection_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_data= "Off" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_windows_smartscreen_protection_filter` [ESCU - Disabling CMD Application - Rule] action.escu = 0 @@ -10218,8 +10218,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = this search is to identify modification in registry to disable cmd prompt application. This technique is commonly seen in RAT, Trojan or WORM to prevent triaging or deleting there samples through cmd application which is one of the tool of analyst to traverse on directory and files. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin may disable this application for non technical user. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disabling CMD Application - Rule action.escu.search_type = detection @@ -10238,7 +10238,7 @@ action.correlationsearch.label = ESCU - Disabling CMD Application - Rule action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = this search is to identify modification in registry to disable cmd prompt application. This technique is commonly seen in RAT, Trojan or WORM to prevent triaging or deleting there samples through cmd application which is one of the tool of analyst to traverse on directory and files. action.notable.param.rule_title = Disabling CMD Application action.notable.param.security_domain = endpoint @@ -10252,7 +10252,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disabling_cmd_application_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_cmd_application_filter` [ESCU - Disabling ControlPanel - Rule] action.escu = 0 @@ -10263,8 +10263,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = this search is to identify registry modification to disable control panel window. This technique is commonly seen in malware to prevent their artifacts , persistence removed on the infected machine. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin may disable this application for non technical user. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Disabling ControlPanel - Rule action.escu.search_type = detection @@ -10283,7 +10283,7 @@ action.correlationsearch.label = ESCU - Disabling ControlPanel - Rule action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = this search is to identify registry modification to disable control panel window. This technique is commonly seen in malware to prevent their artifacts , persistence removed on the infected machine. action.notable.param.rule_title = Disabling ControlPanel action.notable.param.security_domain = endpoint @@ -10297,7 +10297,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_controlpanel_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_controlpanel_filter` [ESCU - Disabling Defender Services - Rule] action.escu = 0 @@ -10308,8 +10308,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = admin or user may choose to disable windows defender product -action.escu.creation_date = 2021-10-20 -action.escu.modification_date = 2021-10-20 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Disabling Defender Services - Rule action.escu.search_type = detection @@ -10342,7 +10342,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*", "*WinDefend*", "*SecurityHealthService*")) AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disabling_defender_services_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*","*WinDefend*", "*SecurityHealthService*")) AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disabling_defender_services_filter` [ESCU - Disabling Firewall with Netsh - Rule] action.escu = 0 @@ -10398,8 +10398,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This search is to identify registry modification to disable folder options feature of windows to show hidden files, file extension and etc. This technique used by malware in combination if disabling show hidden files feature to hide their files and also to hide the file extension to lure the user base on file icons or fake file extensions. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin may disable this application for non technical user. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Disabling FolderOptions Windows Feature - Rule action.escu.search_type = detection @@ -10418,7 +10418,7 @@ action.correlationsearch.label = ESCU - Disabling FolderOptions Windows Feature action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = This search is to identify registry modification to disable folder options feature of windows to show hidden files, file extension and etc. This technique used by malware in combination if disabling show hidden files feature to hide their files and also to hide the file extension to lure the user base on file icons or fake file extensions. action.notable.param.rule_title = Disabling FolderOptions Windows Feature action.notable.param.security_domain = endpoint @@ -10432,7 +10432,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_folderoptions_windows_feature_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_folderoptions_windows_feature_filter` [ESCU - Disabling Net User Account - Rule] action.escu = 0 @@ -10488,8 +10488,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This search is to identify modification of registry to disable run application in window start menu. this application is known to be a helpful shortcut to windows OS user to run known application and also to execute some reg or batch script. This technique is used malware to make cleaning of its infection more harder by preventing known application run easily through run shortcut. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin may disable this application for non technical user. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Disabling NoRun Windows App - Rule action.escu.search_type = detection @@ -10508,7 +10508,7 @@ action.correlationsearch.label = ESCU - Disabling NoRun Windows App - Rule action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 50, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 50, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = This search is to identify modification of registry to disable run application in window start menu. this application is known to be a helpful shortcut to windows OS user to run known application and also to execute some reg or batch script. This technique is used malware to make cleaning of its infection more harder by preventing known application run easily through run shortcut. action.notable.param.rule_title = Disabling NoRun Windows App action.notable.param.security_domain = endpoint @@ -10522,7 +10522,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_norun_windows_app_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_norun_windows_app_filter` [ESCU - Disabling Remote User Account Control - Rule] action.escu = 0 @@ -10578,8 +10578,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = The following search identifies the modification of registry related in disabling the system restore of a machine. This event or behavior are seen in some RAT malware to make the restore of the infected machine difficult and keep their infection on the box. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = in some cases admin can disable systemrestore on a machine. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Disabling SystemRestore In Registry - Rule action.escu.search_type = detection @@ -10598,7 +10598,7 @@ action.correlationsearch.label = ESCU - Disabling SystemRestore In Registry - Ru action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = The following search identifies the modification of registry related in disabling the system restore of a machine. This event or behavior are seen in some RAT malware to make the restore of the infected machine difficult and keep their infection on the box. action.notable.param.rule_title = Disabling SystemRestore In Registry action.notable.param.security_domain = endpoint @@ -10612,7 +10612,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disabling_systemrestore_in_registry_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_systemrestore_in_registry_filter` [ESCU - Disabling Task Manager - Rule] action.escu = 0 @@ -10623,8 +10623,8 @@ action.escu.data_models = ["Endpoint"] action.escu.eli5 = This search is to identifies modification of registry to disable the task manager of windows operating system. this event or technique are commonly seen in malware such as RAT, Trojan, TrojanSpy or worm to prevent the user to terminate their process. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = admin may disable this application for non technical user. -action.escu.creation_date = 2021-03-31 -action.escu.modification_date = 2021-03-31 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Disabling Task Manager - Rule action.escu.search_type = detection @@ -10643,7 +10643,7 @@ action.correlationsearch.label = ESCU - Disabling Task Manager - Rule action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics"], "confidence": 60, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 70, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.001", "T1562"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = This search is to identifies modification of registry to disable the task manager of windows operating system. this event or technique are commonly seen in malware such as RAT, Trojan, TrojanSpy or worm to prevent the user to terminate their process. action.notable.param.rule_title = Disabling Task Manager action.notable.param.security_domain = endpoint @@ -10657,7 +10657,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_task_manager_filter` +search = | tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_task_manager_filter` [ESCU - Domain Account Discovery With Net App - Rule] action.escu = 0 @@ -11512,8 +11512,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic is to detect a registry modification to disable ETW feature of windows. This technique is to evade EDR appliance to evade detections and hide its execution from audit logs. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-10-07 -action.escu.modification_date = 2021-10-07 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - ETW Registry Disabled - Rule action.escu.search_type = detection @@ -11546,7 +11546,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*") Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `etw_registry_disabled_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*" Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `etw_registry_disabled_filter` [ESCU - Elevated Group Discovery With Net - Rule] action.escu = 0 @@ -11814,8 +11814,8 @@ action.escu.data_models = [] action.escu.eli5 = This search is to detect a modification to registry to enable rdp to a machine with different port number. This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-05-19 -action.escu.modification_date = 2021-05-19 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Enable RDP In Other Port Number - Rule action.escu.search_type = detection @@ -11848,7 +11848,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber" by Registry.dest Registry.user Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `enable_rdp_in_other_port_number_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `enable_rdp_in_other_port_number_filter` [ESCU - Enable WDigest UseLogonCredential Registry - Rule] action.escu = 0 @@ -11859,8 +11859,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic is to detect a suspicious registry modification to enable plain text credential feature of windows. This technique was used by several malware and also by mimikatz to be able to dumpe the a plain text credential to the compromised or target host. This TTP is really a good indicator that someone wants to dump the crendential of the host so it must be a good pivot for credential dumping techniques. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-10-05 -action.escu.modification_date = 2021-10-05 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Enable WDigest UseLogonCredential Registry - Rule action.escu.search_type = detection @@ -11893,7 +11893,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `enable_wdigest_uselogoncredential_registry_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `enable_wdigest_uselogoncredential_registry_filter` [ESCU - Enumerate Users Local Group Using Telegram - Rule] action.escu = 0 @@ -11993,8 +11993,8 @@ action.escu.data_models = [] action.escu.eli5 = The following search identifies Eventvwr bypass by identifying the registry modification into a specific path that eventvwr.msc looks to (but is not valid) upon execution. A successful attack will include a suspicious command to be executed upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. action.escu.known_false_positives = Some false positives may be present and will need to be filtered. -action.escu.creation_date = 2021-03-01 -action.escu.modification_date = 2021-03-01 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Eventvwr UAC Bypass - Rule action.escu.search_type = detection @@ -12013,7 +12013,7 @@ action.correlationsearch.label = ESCU - Eventvwr UAC Bypass - Rule action.correlationsearch.annotations = {"analytic_story": ["Windows Defense Evasion Tactics", "IcedID"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Defense Evasion"], "impact": 80, "kill_chain_phases": ["Exploitation", "Privilege Escalation"], "mitre_attack": ["T1548.002", "T1548"], "observable": [{"name": "user", "role": ["Victim"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Hostname"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = The following search identifies Eventvwr bypass by identifying the registry modification into a specific path that eventvwr.msc looks to (but is not valid) upon execution. A successful attack will include a suspicious command to be executed upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. action.notable.param.rule_title = Eventvwr UAC Bypass action.notable.param.security_domain = endpoint @@ -12027,7 +12027,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by Registry.user, Registry.dest , Registry.registry_value_name| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `eventvwr_uac_bypass_filter` +search = | tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `eventvwr_uac_bypass_filter` [ESCU - Excel Spawning PowerShell - Rule] action.escu = 0 @@ -16001,8 +16001,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic identifies a suspicious registry modification to hide a user account on the Windows Login screen. This technique was seen in some tradecraft where the adversary will create a hidden user account with Admin privileges in login screen to avoid noticing by the user that they already compromise and to persist on that said machine. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = Unknown. Filter as needed. -action.escu.creation_date = 2021-05-05 -action.escu.modification_date = 2021-05-05 +action.escu.creation_date = 2022-01-28 +action.escu.modification_date = 2022-01-28 action.escu.confidence = high action.escu.full_search_name = ESCU - Hide User Account From Sign-In Screen - Rule action.escu.search_type = detection @@ -16035,7 +16035,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data = "0x00000000" by Registry.dest Registry.user Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `hide_user_account_from_sign_in_screen_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `hide_user_account_from_sign_in_screen_filter` [ESCU - Hiding Files And Directories With Attrib exe - Rule] action.escu = 0 @@ -23339,6 +23339,51 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wmiprvse.exe OR Processes.parent_process_name=services.exe OR Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wsmprovhost.exe OR Processes.parent_process_name=mmc.exe) (Processes.process_name=powershell.exe OR (Processes.process_name=cmd.exe AND Processes.process=*powershell.exe*) OR Processes.process_name=pwsh.exe OR (Processes.process_name=cmd.exe AND Processes.process=*pwsh.exe*)) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `possible_lateral_movement_powershell_spawn_filter` +[ESCU - Potentially malicious code on commandline - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytic uses a pretrained machine learning text classifier to detect potentially malicious commandlines. The model identifies unusual combinations of keywords found in samples of commandlines where adversaries executed powershell code, primarily for C2 communication. For example, adversaries will leverage IO capabilities such as "streamreader" and "webclient", threading capabilties such as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically found in normal usage of the commandline. The model will output a score where all values above zero are suspicious, anything greater than one particularly so. +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003"]} +action.escu.data_models = ["\"Endpoint"] +action.escu.eli5 = The following analytic uses a pretrained machine learning text classifier to detect potentially malicious commandlines. The model identifies unusual combinations of keywords found in samples of commandlines where adversaries executed powershell code, primarily for C2 communication. For example, adversaries will leverage IO capabilities such as "streamreader" and "webclient", threading capabilties such as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically found in normal usage of the commandline. The model will output a score where all values above zero are suspicious, anything greater than one particularly so. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. You will also need to install the Machine Learning Toolkit version 5.3 or above to apply the pretrained model. +action.escu.known_false_positives = This model is an anomaly detector that identifies usage of APIs and scripting constructs that are correllated with malicious activity. These APIs and scripting constructs are part of the programming langauge and advanced scripts may generate false positives. +action.escu.creation_date = 2022-01-14 +action.escu.modification_date = 2022-01-14 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Potentially malicious code on commandline - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Suspicious Command-Line Executions"] +action.risk = 1 +action.risk.param._risk_message = Unusual command-line execution with hallmarks of malicious activity run by $user$ found on $dest$ with commandline $process$ +action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 12}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 12}] +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Potentially malicious code on commandline - Rule +action.correlationsearch.annotations = {"analytic_story": ["Suspicious Command-Line Executions"], "confidence": 20, "context": ["source:endpoint", "stage:Execution"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1059.003"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Hostname"}, {"name": "user", "role": ["Victim"], "type": "User"}]} +schedule_window = auto +action.notable = 1 +action.notable.param.nes_fields = ['user', 'dest'] +action.notable.param.rule_description = The following analytic uses a pretrained machine learning text classifier to detect potentially malicious commandlines. The model identifies unusual combinations of keywords found in samples of commandlines where adversaries executed powershell code, primarily for C2 communication. For example, adversaries will leverage IO capabilities such as "streamreader" and "webclient", threading capabilties such as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically found in normal usage of the commandline. The model will output a score where all values above zero are suspicious, anything greater than one particularly so. +action.notable.param.rule_title = Potentially malicious code on commandline +action.notable.param.security_domain = endpoint +action.notable.param.severity = high +alert.digest_mode = 1 +disabled = true +enableSched = 1 +allow_skew = 100% +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` | where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score` | apply unusual_commandline_detection | eval score='predicted(unusual_cmdline_logits)', process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits) orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `potentially_malicious_code_on_commandline_filter` + [ESCU - PowerShell - Connect To Internet With Hidden Window - Rule] action.escu = 0 action.escu.enabled = 1 @@ -25225,8 +25270,8 @@ action.escu.data_models = [] action.escu.eli5 = The search looks for modifications to registry keys that can be used to launch an application or service at system startup. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = There are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task. -action.escu.creation_date = 2021-09-07 -action.escu.modification_date = 2021-09-07 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Registry Keys Used For Persistence - Rule action.escu.search_type = detection @@ -25259,7 +25304,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `registry_keys_used_for_persistence_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `registry_keys_used_for_persistence_filter` [ESCU - Registry Keys Used For Privilege Escalation - Rule] action.escu = 0 @@ -25270,8 +25315,8 @@ action.escu.data_models = [] action.escu.eli5 = This search looks for modifications to registry keys that can be used to elevate privileges. The registry keys under "Image File Execution Options" are used to intercept calls to an executable and can be used to attach malicious binaries to benign system binaries. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = There are many legitimate applications that must execute upon system startup and will use these registry keys to accomplish that task. -action.escu.creation_date = 2020-11-27 -action.escu.modification_date = 2020-11-27 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Registry Keys Used For Privilege Escalation - Rule action.escu.search_type = detection @@ -25304,7 +25349,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger) by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `registry_keys_used_for_privilege_escalation_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `registry_keys_used_for_privilege_escalation_filter` [ESCU - Registry Keys for Creating SHIM Databases - Rule] action.escu = 0 @@ -25495,8 +25540,8 @@ action.escu.data_models = [] action.escu.eli5 = This search detects registry key license at host where Remcos RAT agent is installed. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-09-24 -action.escu.modification_date = 2021-09-24 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Remcos client registry install entry - Rule action.escu.search_type = detection @@ -25529,7 +25574,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Registry.registry_path) as registry_path FROM datamodel=Endpoint.Registry where (Registry.registry_key_name=*\\Software\\Remcos*) by Registry.dest Registry.user Registry.registry_key_name Registry.process_id| `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`|`remcos_client_registry_install_entry_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_key_name=*\\Software\\Remcos*) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data |`remcos_client_registry_install_entry_filter` [ESCU - Remote Desktop Network Bruteforce - Rule] action.escu = 0 @@ -26375,8 +26420,8 @@ action.escu.data_models = [] action.escu.eli5 = This analytic identifies suspicious modification in registry entry to keep some malware data during its infection. This technique seen in several apt implant, malware and ransomware like REVIL where it keep some information like the random generated file extension it uses for all the encrypted files and ransomware notes file name in the compromised host. action.escu.how_to_implement = to successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-06-02 -action.escu.modification_date = 2021-06-02 +action.escu.creation_date = 2021-01-26 +action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Revil Registry Entry - Rule action.escu.search_type = detection @@ -26409,7 +26454,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") AND (Registry.registry_value_name = "\.*" OR Registry.registry_value_name = "Binary Data") by Registry.registry_value_name Registry.dest Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `revil_registry_entry_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `revil_registry_entry_filter` [ESCU - RunDLL Loading DLL By Ordinal - Rule] action.escu = 0 @@ -28934,8 +28979,8 @@ action.escu.data_models = [] action.escu.eli5 = This search is to detect a modification or registry add to the safeboot registry as an autostart mechanism. This technique was seen in some ransomware to automatically execute its code upon a safe mode boot. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = updated windows application needed in safe boot may used this registry -action.escu.creation_date = 2021-06-10 -action.escu.modification_date = 2021-06-10 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Start Up During Safe Mode Boot - Rule action.escu.search_type = detection @@ -28954,7 +28999,7 @@ action.correlationsearch.label = ESCU - Start Up During Safe Mode Boot - Rule action.correlationsearch.annotations = {"analytic_story": ["Ransomware"], "confidence": 70, "context": ["Source:Endpoint", "Stage:Persistence"], "impact": 60, "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.001", "T1547"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = ['dest'] +action.notable.param.nes_fields = ['user', 'dest'] action.notable.param.rule_description = This search is to detect a modification or registry add to the safeboot registry as an autostart mechanism. This technique was seen in some ransomware to automatically execute its code upon a safe mode boot. action.notable.param.rule_title = Start Up During Safe Mode Boot action.notable.param.security_domain = endpoint @@ -28968,7 +29013,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `start_up_during_safe_mode_boot_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `start_up_during_safe_mode_boot_filter` [ESCU - Sunburst Correlation DLL and Network Event - Rule] action.escu = 0 @@ -31256,14 +31301,14 @@ search = | tstats `security_content_summariesonly` count min(_time) as firstTime [ESCU - Time Provider Persistence Registry - Rule] action.escu = 0 action.escu.enabled = 1 -description = This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. +description = This analytic is to detect a suspicious modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.003", "T1547"]} action.escu.data_models = [] -action.escu.eli5 = This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. +action.escu.eli5 = This analytic is to detect a suspicious modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. action.escu.how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. action.escu.known_false_positives = unknown -action.escu.creation_date = 2021-09-29 -action.escu.modification_date = 2021-09-29 +action.escu.creation_date = 2022-01-26 +action.escu.modification_date = 2022-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Time Provider Persistence Registry - Rule action.escu.search_type = detection @@ -31283,7 +31328,7 @@ action.correlationsearch.annotations = {"analytic_story": ["Windows Persistence schedule_window = auto action.notable = 1 action.notable.param.nes_fields = ['user', 'dest'] -action.notable.param.rule_description = This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. +action.notable.param.rule_description = This analytic is to detect a suspicious modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. action.notable.param.rule_title = Time Provider Persistence Registry action.notable.param.security_domain = endpoint action.notable.param.severity = high @@ -31296,7 +31341,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `time_provider_persistence_registry_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `time_provider_persistence_registry_filter` [ESCU - Trickbot Named Pipe - Rule] action.escu = 0 @@ -34111,9 +34156,9 @@ CallTrace Stack trace of where open process is called. Included is the DLL and t dbgcore.dll or dbghelp.dll are two core Windows debug DLLs that have minidump functions which provide a way for applications to produce crashdump files that contain a useful subset of the entire process context. \ The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll. For example in sekurlsa module there are many ntdll exported api, like RtlCopyMemory, used to execute this module which is related to lsass dumping. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Enabling EventCode 10 TargetProcess lsass.exe is required. -action.escu.known_false_positives = False positives will occur based on GrantedAccess, filter based on source image as needed. -action.escu.creation_date = 2022-01-10 -action.escu.modification_date = 2022-01-10 +action.escu.known_false_positives = False positives will occur based on GrantedAccess 0x1010 and 0x1400, filter based on source image as needed or remove them. Concern is Cobalt Strike usage of Mimikatz will generate 0x1010 initially, but later be caught. +action.escu.creation_date = 2022-01-27 +action.escu.modification_date = 2022-01-27 action.escu.confidence = high action.escu.full_search_name = ESCU - Windows Possible Credential Dumping - Rule action.escu.search_type = detection @@ -34150,7 +34195,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess IN ("0x01000", "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x1438", "0x143a", "0x1438", "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") | stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser | rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_possible_credential_dumping_filter` +search = `sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess IN ("0x01000", "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438", "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") | stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser | rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_possible_credential_dumping_filter` [ESCU - Windows Raccine Scheduled Task Deletion - Rule] action.escu = 0 diff --git a/dist/escu/default/transforms.conf b/dist/escu/default/transforms.conf index 24d1e46fcd..a3d7ed71f5 100644 --- a/dist/escu/default/transforms.conf +++ b/dist/escu/default/transforms.conf @@ -1,10 +1,17 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2022-01-26T22:49:42 UTC +# On Date: 2022-01-31T19:58:16 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# +[__mlspl_unusual_commandline_detection] +filename = __mlspl_unusual_commandline_detection.mlmodel +default_match = false +case_sensitive_match = false +# description = An MLTK model for detecting malicious commandlines +min_matches = 1 + [api_call_by_user_baseline] collection = api_call_by_user_baseline external_type = kvstore @@ -223,6 +230,12 @@ filename = previously_seen_cmd_line_arguments.csv filename = previously_seen_ec2_modifications_by_user.csv # description = A place holder for a list of AWS EC2 modifications done by each user +[previously_seen_gcp_storage_access_from_remote_ip] +filename = previously_seen_gcp_storage_access_from_remote_ip.csv +default_match = false +# description = A place holder for a list of GCP storage access from remote IPs +min_matches = 1 + [previously_seen_running_windows_services] collection = previously_seen_running_windows_services external_type = kvstore diff --git a/dist/escu/lookups/__mlspl_unusual_commandline_detection.mlmodel b/dist/escu/lookups/__mlspl_unusual_commandline_detection.mlmodel new file mode 100644 index 0000000000..e214415ae0 --- /dev/null +++ b/dist/escu/lookups/__mlspl_unusual_commandline_detection.mlmodel @@ -0,0 +1,2 @@ +algo,model,options +LinearRegression,"{""__mlspl_type"": [""algos.LinearRegression"", ""LinearRegression""], ""dict"": {""estimator"": {""__mlspl_type"": [""sklearn.linear_model._base"", ""LinearRegression""], ""dict"": {""fit_intercept"": true, ""normalize"": false, ""copy_X"": true, ""n_jobs"": null, ""intercept_"": -1.2124304031951825, ""coef_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGY4JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDM2LCksIH0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIApreM9kKtnhP0TDf2w1t+I/3qDHjxK61j8UkPlxGST1v/rMDbO+a8e/iv8JpC2l5T+6dz+pdS3nP0mN7wQ8eO0/UqU3sakDyD9ncnkR3LHzP/6iGnNrQO2/z3R1+fFX9D/5ZfOERzTQv+rvqnTxzfO/979MJJkR378n6CfDQdDYP2XRpM7gmNi/pOwWahfc5j+sabiuJ0vyv8l3R09uZf+/tJflJH4LC0AXzFbk2d7RP61rdIKV+AHAtoJRDnX89b8AAAAAAAAAAHjIjMQz+ec/tHGBbk/z8r8epfEwzMwNwFdDZaNuDOI/9b/zguLg5z/5me57PV71vy3iI7chKeg/aPI+jdvl6z94yIzEM/nnP1kSQcEw/NE/TItteBKa4T8=""}}}, ""columns"": [""unusual_cmdline_feature_for"", ""unusual_cmdline_feature_netsh"", ""unusual_cmdline_feature_readbytes"", ""unusual_cmdline_feature_set"", ""unusual_cmdline_feature_unrestricted"", ""unusual_cmdline_feature_winstations"", ""unusual_cmdline_feature_-value"", ""unusual_cmdline_feature_compression"", ""unusual_cmdline_feature_server"", ""unusual_cmdline_feature_set-mppreference"", ""unusual_cmdline_feature_terminal"", ""unusual_cmdline_feature_-name"", ""unusual_cmdline_feature_catch"", ""unusual_cmdline_feature_get-wmiobject"", ""unusual_cmdline_feature_hklm"", ""unusual_cmdline_feature_streamreader"", ""unusual_cmdline_feature_system32"", ""unusual_cmdline_feature_username"", ""unusual_cmdline_feature_webrequest"", ""unusual_cmdline_feature_count"", ""unusual_cmdline_feature_webclient"", ""unusual_cmdline_feature_writeallbytes"", ""unusual_cmdline_feature_convert"", ""unusual_cmdline_feature_create"", ""unusual_cmdline_feature_function"", ""unusual_cmdline_feature_net"", ""unusual_cmdline_feature_com"", ""unusual_cmdline_feature_http"", ""unusual_cmdline_feature_io"", ""unusual_cmdline_feature_system"", ""unusual_cmdline_feature_new-object"", ""unusual_cmdline_feature_if"", ""unusual_cmdline_feature_threading"", ""unusual_cmdline_feature_mutex"", ""unusual_cmdline_feature_cryptography"", ""unusual_cmdline_feature_computehash""], ""target_variable"": ""unusual_cmdline_logits"", ""feature_variables"": [""unusual_cmdline_feature_for"", ""unusual_cmdline_feature_netsh"", ""unusual_cmdline_feature_readbytes"", ""unusual_cmdline_feature_set"", ""unusual_cmdline_feature_unrestricted"", ""unusual_cmdline_feature_winstations"", ""unusual_cmdline_feature_-value"", ""unusual_cmdline_feature_compression"", ""unusual_cmdline_feature_server"", ""unusual_cmdline_feature_set-mppreference"", ""unusual_cmdline_feature_terminal"", ""unusual_cmdline_feature_-name"", ""unusual_cmdline_feature_catch"", ""unusual_cmdline_feature_get-wmiobject"", ""unusual_cmdline_feature_hklm"", ""unusual_cmdline_feature_streamreader"", ""unusual_cmdline_feature_system32"", ""unusual_cmdline_feature_username"", ""unusual_cmdline_feature_webrequest"", ""unusual_cmdline_feature_count"", ""unusual_cmdline_feature_webclient"", ""unusual_cmdline_feature_writeallbytes"", ""unusual_cmdline_feature_convert"", ""unusual_cmdline_feature_create"", ""unusual_cmdline_feature_function"", ""unusual_cmdline_feature_net"", ""unusual_cmdline_feature_com"", ""unusual_cmdline_feature_http"", ""unusual_cmdline_feature_io"", ""unusual_cmdline_feature_system"", ""unusual_cmdline_feature_new-object"", ""unusual_cmdline_feature_if"", ""unusual_cmdline_feature_threading"", ""unusual_cmdline_feature_mutex"", ""unusual_cmdline_feature_cryptography"", ""unusual_cmdline_feature_computehash""]}}","{""args"": [""unusual_cmdline_logits"", ""unusual_cmdline_feature_for"", ""unusual_cmdline_feature_netsh"", ""unusual_cmdline_feature_readbytes"", ""unusual_cmdline_feature_set"", ""unusual_cmdline_feature_unrestricted"", ""unusual_cmdline_feature_winstations"", ""unusual_cmdline_feature_-value"", ""unusual_cmdline_feature_compression"", ""unusual_cmdline_feature_server"", ""unusual_cmdline_feature_set-mppreference"", ""unusual_cmdline_feature_terminal"", ""unusual_cmdline_feature_-name"", ""unusual_cmdline_feature_catch"", ""unusual_cmdline_feature_get-wmiobject"", ""unusual_cmdline_feature_hklm"", ""unusual_cmdline_feature_streamreader"", ""unusual_cmdline_feature_system32"", ""unusual_cmdline_feature_username"", ""unusual_cmdline_feature_webrequest"", ""unusual_cmdline_feature_count"", ""unusual_cmdline_feature_webclient"", ""unusual_cmdline_feature_writeallbytes"", ""unusual_cmdline_feature_convert"", ""unusual_cmdline_feature_create"", ""unusual_cmdline_feature_function"", ""unusual_cmdline_feature_net"", ""unusual_cmdline_feature_com"", ""unusual_cmdline_feature_http"", ""unusual_cmdline_feature_io"", ""unusual_cmdline_feature_system"", ""unusual_cmdline_feature_new-object"", ""unusual_cmdline_feature_if"", ""unusual_cmdline_feature_threading"", ""unusual_cmdline_feature_mutex"", ""unusual_cmdline_feature_cryptography"", ""unusual_cmdline_feature_computehash""], ""target_variable"": [""unusual_cmdline_logits""], ""feature_variables"": [""unusual_cmdline_feature_for"", ""unusual_cmdline_feature_netsh"", ""unusual_cmdline_feature_readbytes"", ""unusual_cmdline_feature_set"", ""unusual_cmdline_feature_unrestricted"", ""unusual_cmdline_feature_winstations"", ""unusual_cmdline_feature_-value"", ""unusual_cmdline_feature_compression"", ""unusual_cmdline_feature_server"", ""unusual_cmdline_feature_set-mppreference"", ""unusual_cmdline_feature_terminal"", ""unusual_cmdline_feature_-name"", ""unusual_cmdline_feature_catch"", ""unusual_cmdline_feature_get-wmiobject"", ""unusual_cmdline_feature_hklm"", ""unusual_cmdline_feature_streamreader"", ""unusual_cmdline_feature_system32"", ""unusual_cmdline_feature_username"", ""unusual_cmdline_feature_webrequest"", ""unusual_cmdline_feature_count"", ""unusual_cmdline_feature_webclient"", ""unusual_cmdline_feature_writeallbytes"", ""unusual_cmdline_feature_convert"", ""unusual_cmdline_feature_create"", ""unusual_cmdline_feature_function"", ""unusual_cmdline_feature_net"", ""unusual_cmdline_feature_com"", ""unusual_cmdline_feature_http"", ""unusual_cmdline_feature_io"", ""unusual_cmdline_feature_system"", ""unusual_cmdline_feature_new-object"", ""unusual_cmdline_feature_if"", ""unusual_cmdline_feature_threading"", ""unusual_cmdline_feature_mutex"", ""unusual_cmdline_feature_cryptography"", ""unusual_cmdline_feature_computehash""], ""model_name"": ""lm_avg_char_prob"", ""algo_name"": ""LinearRegression"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""1000"", ""max_model_size_mb"": ""15"", ""max_score_time"": ""600"", ""streaming_apply"": ""false"", ""use_sampling"": ""true""}, ""kfold_cv"": null}" diff --git a/dist/escu/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv b/dist/escu/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv new file mode 100644 index 0000000000..8a5c209fa3 --- /dev/null +++ b/dist/escu/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv @@ -0,0 +1 @@ +firstTime, lastTime, bucket_name, remote_ip, operation, request_uri \ No newline at end of file diff --git a/docs/_data/navigation.yml b/docs/_data/navigation.yml index 50655b7c09..c0eb147ba8 100644 --- a/docs/_data/navigation.yml +++ b/docs/_data/navigation.yml @@ -56,6 +56,8 @@ detections: url: /detections/endpoint_filesystem/ - title: Endpoint_Processes url: /detections/endpoint_processes/ + - title: Endpoint_Registry + url: /detections/endpoint_registry/ - title: Network_Resolution url: /detections/network_resolution/ - title: Network_Sessions diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md index 7a66253d59..ed41eae6f1 100644 --- a/docs/_pages/detections.md +++ b/docs/_pages/detections.md @@ -51,6 +51,7 @@ sidebar: | [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Amazon EKS Kubernetes Pod scan detection](/cloud/amazon_eks_kubernetes_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | Hunting | | [Amazon EKS Kubernetes cluster scan detection](/cloud/amazon_eks_kubernetes_cluster_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | Hunting | +| [Anomalous Usage of Account Credentials](/endpoint/anomalous_usage_of_account_credentials/) | [Domain Accounts](/tags/#domain-accounts) | Anomaly | | [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Anomaly | | [Anomalous usage of Archive Tools](/endpoint/anomalous_usage_of_archive_tools/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Anomaly | | [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | @@ -85,6 +86,7 @@ sidebar: | [Circle CI Disable Security Job](/cloud/circle_ci_disable_security_job/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | Anomaly | | [Circle CI Disable Security Step](/cloud/circle_ci_disable_security_step/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | Anomaly | | [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Clop Common Exec Parameter](/endpoint/clop_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | | [Clop Ransomware Known Service Name](/endpoint/clop_ransomware_known_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Cloud API Calls From Previously Unseen User Roles](/cloud/cloud_api_calls_from_previously_unseen_user_roles/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | @@ -216,6 +218,7 @@ sidebar: | [Detection of tools built by NirSoft](/endpoint/detection_of_tools_built_by_nirsoft/) | [Software Deployment Tools](/tags/#software-deployment-tools) | TTP | | [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Defender AntiVirus Registry](/endpoint/disable_defender_antivirus_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Defender AntiVirus Registry](/experimental/disable_defender_antivirus_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Defender BlockAtFirstSeen Feature](/endpoint/disable_defender_blockatfirstseen_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Defender Enhanced Notification](/endpoint/disable_defender_enhanced_notification/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Defender MpEngine Registry](/endpoint/disable_defender_mpengine_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | @@ -355,6 +358,7 @@ sidebar: | [Gsuite suspicious calendar invite](/cloud/gsuite_suspicious_calendar_invite/) | [Phishing](/tags/#phishing) | Hunting | | [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [High File Deletion Frequency](/endpoint/high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction) | Anomaly | | [High File Deletion Frequency](/endpoint/high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction) | Anomaly | | [High Frequency Copy Of Files In Network Share](/endpoint/high_frequency_copy_of_files_in_network_share/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | Anomaly | @@ -501,6 +505,7 @@ sidebar: | [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell) | TTP | | [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | | [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Potentially malicious code on commandline](/endpoint/potentially_malicious_code_on_commandline/) | [Windows Command Shell](/tags/#windows-command-shell) | Anomaly | | [PowerShell - Connect To Internet With Hidden Window](/endpoint/powershell_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Hunting | | [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | Hunting | | [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | diff --git a/docs/_pages/endpoint_registry.md b/docs/_pages/endpoint_registry.md new file mode 100644 index 0000000000..9c10f41486 --- /dev/null +++ b/docs/_pages/endpoint_registry.md @@ -0,0 +1,9 @@ +--- +title: Endpoint_Registry +layout: tag +author_profile: false +taxonomy: Endpoint_Registry +permalink: /detections/endpoint_registry/ +sidebar: + nav: "detections" +--- \ No newline at end of file diff --git a/docs/_playbooks/delete_detected_files.md b/docs/_playbooks/delete_detected_files.md index 8908bf299b..030af20a60 100644 --- a/docs/_playbooks/delete_detected_files.md +++ b/docs/_playbooks/delete_detected_files.md @@ -293,6 +293,9 @@ This playbook acts upon events where a file has been determined to be malicious + + + @@ -769,6 +772,8 @@ This playbook acts upon events where a file has been determined to be malicious + + diff --git a/docs/_playbooks/log4j_investigate.md b/docs/_playbooks/log4j_investigate.md index 412af4c65a..33a0c299ff 100644 --- a/docs/_playbooks/log4j_investigate.md +++ b/docs/_playbooks/log4j_investigate.md @@ -123,6 +123,8 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + @@ -1456,6 +1458,14 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + + + + + @@ -1891,6 +1901,10 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + @@ -3355,6 +3369,16 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + + + + + + + @@ -4228,6 +4252,11 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + + @@ -4899,6 +4928,11 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + + @@ -5647,6 +5681,11 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + + @@ -6145,6 +6184,9 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + @@ -6742,6 +6784,9 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + diff --git a/docs/_playbooks/log4j_respond.md b/docs/_playbooks/log4j_respond.md index e2f2e4ab39..e0d3abe546 100644 --- a/docs/_playbooks/log4j_respond.md +++ b/docs/_playbooks/log4j_respond.md @@ -123,6 +123,8 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + @@ -1456,6 +1458,14 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + + + + + @@ -1891,6 +1901,10 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + @@ -3355,6 +3369,16 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + + + + + + + @@ -4228,6 +4252,11 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + + @@ -4899,6 +4928,11 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + + @@ -5647,6 +5681,11 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + + @@ -6145,6 +6184,9 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + @@ -6742,6 +6784,9 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + diff --git a/docs/_playbooks/ransomware_investigate_and_contain.md b/docs/_playbooks/ransomware_investigate_and_contain.md index 0e8c266216..8abf8e815a 100644 --- a/docs/_playbooks/ransomware_investigate_and_contain.md +++ b/docs/_playbooks/ransomware_investigate_and_contain.md @@ -115,6 +115,8 @@ This playbook investigates and contains ransomware detected on endpoints. + + @@ -772,6 +774,9 @@ This playbook investigates and contains ransomware detected on endpoints. + + + diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md index aabb178903..62ae2cb2f1 100644 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md @@ -51,9 +51,9 @@ This search looks at GCP Storage bucket-access logs and detects new or previousl | search status="\"200\"" | stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip operation request_uri | table firstTime, lastTime, bucket_name, remote_ip, operation, request_uri -| inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip.csv +| inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip | stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip operation request_uri -| outputlookup previously_seen_gcp_storage_access_from_remote_ip.csv +| outputlookup previously_seen_gcp_storage_access_from_remote_ip | eval newIP=if(firstTime >= relative_time(now(),"-70m@m"), 1, 0) | where newIP=1 | eval first_time=strftime(firstTime,"%m/%d/%y %H:%M:%S") diff --git a/docs/_posts/2021-06-02-revil_registry_entry.md b/docs/_posts/2021-01-26-revil_registry_entry.md similarity index 74% rename from docs/_posts/2021-06-02-revil_registry_entry.md rename to docs/_posts/2021-01-26-revil_registry_entry.md index 51f3caa2d1..adb1a7bf8b 100644 --- a/docs/_posts/2021-06-02-revil_registry_entry.md +++ b/docs/_posts/2021-01-26-revil_registry_entry.md @@ -3,7 +3,7 @@ title: "Revil Registry Entry" excerpt: "Modify Registry" categories: - Endpoint -last_modified_at: 2021-06-02 +last_modified_at: 2021-01-26 toc: true toc_label: "" tags: @@ -26,7 +26,7 @@ This analytic identifies suspicious modification in registry entry to keep some - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-02 +- **Last Updated**: 2021-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: e3d3f57a-c381-11eb-9e35-acde48001122 @@ -41,10 +41,15 @@ This analytic identifies suspicious modification in registry entry to keep some ``` -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") AND (Registry.registry_value_name = "\.*" OR Registry.registry_value_name = "Binary Data") by Registry.registry_value_name Registry.dest Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\Facebook_Assistant\\*" OR Registry.registry_path="*\\SOFTWARE\\WOW6432Node\\BlackLivesMatter*") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `revil_registry_entry_filter` ``` @@ -97,4 +102,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/revil_registry_entry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/revil_registry_entry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md b/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md new file mode 100644 index 0000000000..41a4dc501e --- /dev/null +++ b/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md @@ -0,0 +1,102 @@ +--- +title: "Anomalous Usage of Account Credentials" +excerpt: "Domain Accounts" +categories: + - Endpoint +last_modified_at: 2021-12-07 +toc: true +toc_label: "" +tags: + - Domain Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This is an anomaly generating detection looking for multiple interactive logins within a specific time period. An insider threat may attempt to steal colleagues credentials in low tech, undetectable methods, in order to gain access to additional information or to hide their own behavior. This should capture their attempted use of those credentials on a workstation. + +- **Type**: Anomaly +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-07 +- **Author**: Lou Stella, Splunk +- **ID**: 629cbf9e-5785-11ec-9611-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +#### Search + +``` + +| from read_ssa_enriched_events() +| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), auth_type=ucast(map_get(input_event, "authentication_type"), "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), src_user=ucast(map_get(input_event, "dest_user_original_artifact"), "string", null), signature_id=ucast(map_get(input_event, "EventCode"), "string", null) +| where signature_id="4624" +| where auth_type="2" OR auth_type="11" +| where NOT (src_user="SYSTEM") AND NOT (src_user="ANONYMOUS LOGON") +| stats estdc(src_user) AS user_counter by device, span(timestamp, 600s, 300s) +| where user_counter>=2 +| rename window_end AS timestamp +| eval start_time=window_start, end_time=timestamp, entities=mvappend(device), body=create_map(["user_counter", user_counter, "device", device]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Insider Threat](/stories/insider_threat) + + +#### How To Implement +To successfully implement this detection, you need to be ingesting logon events from workstations. + +#### Required field +* _time + + +#### Kill Chain Phase +* Privilege Escalation +* Lateral Movement + + +#### Known False Positives +Shared workstations can cause false positives + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 6.0 | 20 | 30 | Multiple interactive logins detected on $device$ | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1078/002/](https://attack.mitre.org/techniques/T1078/002/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_login/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_login/windows-security.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/anomalous_usage_of_account_credentials.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md b/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md new file mode 100644 index 0000000000..0c8d18a410 --- /dev/null +++ b/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md @@ -0,0 +1,103 @@ +--- +title: "Disable Defender AntiVirus Registry" +excerpt: "Disable or Modify Tools, Impair Defenses" +categories: + - Experimental +last_modified_at: 2021-12-08 +toc: true +toc_label: "" +tags: + - Disable or Modify Tools + - Defense Evasion + - Impair Defenses + - Defense Evasion + - Splunk Behavioral Analytics + - Endpoint_Registry +--- + +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This particular behavior is typically executed when an adversaries or malware gains access to an endpoint and beings to perform execution and to evade detections. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Registry](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointRegistry) +- **Last Updated**: 2021-12-08 +- **Author**: Bhavin Patel, Splunk +- **ID**: aa4f115a-3024-11ec-9987-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | + +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + +#### Search + +``` + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event,"_time"), "string", null)), registry_path=lower(ucast(map_get(input_event, "registry_path"), "string", null)), registry_key_name=lower(ucast(map_get(input_event, "registry_key_name"), "string", null)), registry_value_data=ucast(map_get(input_event, "registry_value_data"), "string", null), process_guid=ucast(map_get(input_event, "process_guid"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where like(registry_path, "%\\Policies\\Microsoft\\Windows Defender%") AND registry_key_name="DisableAntiVirus" AND registry_value_data="(0x00000001)" +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map( [ "event_id", event_id, "registry_path", registry_path, "registry_key_name", registry_key_name, "process_guid", process_guid,"registry_value_data",registry_value_data]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [IceID](/stories/iceid) + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_value_name +* Registry.registry_key_name +* Registry.registry_path +* Registry.registry_value_data + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Admin or user may choose to disable windows defender product + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 49.0 | 70 | 70 | Modified/added/deleted registry entry $registry_path$ in $dest$ | + + + + +#### Reference + +* [https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/](https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/experimental/disable_defender_antivirus_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md new file mode 100644 index 0000000000..4d302f72d4 --- /dev/null +++ b/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md @@ -0,0 +1,108 @@ +--- +title: "Clear Unallocated Sector Using Cipher App" +excerpt: "File Deletion, Indicator Removal on Host" +categories: + - Endpoint +last_modified_at: 2021-12-20 +toc: true +toc_label: "" +tags: + - File Deletion + - Defense Evasion + - Indicator Removal on Host + - Defense Evasion + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +this search is to detect execution of `cipher.exe` to clear the unallocated sectors of a specific disk. This technique was seen in some ransomware to make it impossible to forensically recover deleted files. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-20 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 8f907d90-6173-11ec-9c23-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | + +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | + +#### Search + +``` + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where cmd_line IS NOT NULL AND like(cmd_line, "%/w:%") AND process_name="cipher.exe" +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Ransomware](/stories/ransomware) +* [Information Sabotage](/stories/information_sabotage) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +administrator may execute this app to manage disk + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors of a specific disk. | + + + + +#### Reference + +* [https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/](https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/) +* [https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf](https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/sophoslabs-ransomware-behavior-report.pdf) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md new file mode 100644 index 0000000000..487c5ce400 --- /dev/null +++ b/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md @@ -0,0 +1,97 @@ +--- +title: "Hiding Files And Directories With Attrib exe" +excerpt: "Windows File and Directory Permissions Modification, File and Directory Permissions Modification" +categories: + - Endpoint +last_modified_at: 2021-12-20 +toc: true +toc_label: "" +tags: + - Windows File and Directory Permissions Modification + - Defense Evasion + - File and Directory Permissions Modification + - Defense Evasion + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Attackers leverage an existing Windows binary, attrib.exe, to mark specific as hidden by using specific flags so that the victim does not see the file. The search looks for specific command-line arguments to detect the use of attrib.exe to hide files. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-20 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 028e4406-6176-11ec-aec2-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1222.001](https://attack.mitre.org/techniques/T1222/001/) | Windows File and Directory Permissions Modification | Defense Evasion | + +| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | + +#### Search + +``` + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where cmd_line IS NOT NULL AND like(cmd_line, "%+h%") AND process_name="attrib.exe" +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Information Sabotage](/stories/information_sabotage) + + +#### How To Implement +You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. + +#### Required field +* _time + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Some applications and users may legitimately use attrib.exe to interact with the files. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 72.0 | 80 | 90 | Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. | + + + + +#### Reference + +* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/attrib](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/attrib) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/attrib_hidden/security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/attrib_hidden/security.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md b/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md new file mode 100644 index 0000000000..c888df60b9 --- /dev/null +++ b/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md @@ -0,0 +1,106 @@ +--- +title: "Potentially malicious code on commandline" +excerpt: "Windows Command Shell" +categories: + - Endpoint +last_modified_at: 2022-01-14 +toc: true +toc_label: "" +tags: + - Windows Command Shell + - Execution + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic uses a pretrained machine learning text classifier to detect potentially malicious commandlines. The model identifies unusual combinations of keywords found in samples of commandlines where adversaries executed powershell code, primarily for C2 communication. For example, adversaries will leverage IO capabilities such as "streamreader" and "webclient", threading capabilties such as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically found in normal usage of the commandline. The model will output a score where all values above zero are suspicious, anything greater than one particularly so. + +- **Type**: Anomaly +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2022-01-14 +- **Author**: Michael Hart, Splunk +- **ID**: 9c53c446-757e-11ec-871d-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name Processes.process_name Processes.process Processes.user Processes.dest +| `drop_dm_object_name(Processes)` +| where len(process) > 200 +| `potentially_malicious_code_on_cmdline_tokenize_score` +| apply unusual_commandline_detection +| eval score='predicted(unusual_cmdline_logits)', process=orig_process +| fields - unusual_cmdline* predicted(unusual_cmdline_logits) orig_process +| where score > 0.5 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `potentially_malicious_code_on_commandline_filter` +``` + +#### Associated Analytic Story +* [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions) + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. You will also need to install the Machine Learning Toolkit version 5.3 or above to apply the pretrained model. + +#### Required field +* _time +* Processes.process +* Processes.parent_process_name +* Processes.process_name +* Processes.parent_process +* Processes.user +* Processes.dest + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +This model is an anomaly detector that identifies usage of APIs and scripting constructs that are correllated with malicious activity. These APIs and scripting constructs are part of the programming langauge and advanced scripts may generate false positives. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 12.0 | 60 | 20 | Unusual command-line execution with hallmarks of malicious activity run by $user$ found on $dest$ with commandline $process$ | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1059/003/](https://attack.mitre.org/techniques/T1059/003/) +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-28-active_setup_registry_autostart.md b/docs/_posts/2022-01-26-active_setup_registry_autostart.md similarity index 78% rename from docs/_posts/2021-09-28-active_setup_registry_autostart.md rename to docs/_posts/2022-01-26-active_setup_registry_autostart.md index 9f5ecd9579..cda3d5f19d 100644 --- a/docs/_posts/2021-09-28-active_setup_registry_autostart.md +++ b/docs/_posts/2022-01-26-active_setup_registry_autostart.md @@ -3,7 +3,7 @@ title: "Active Setup Registry Autostart" excerpt: "Active Setup, Boot or Logon Autostart Execution" categories: - Endpoint -last_modified_at: 2021-09-28 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -30,7 +30,7 @@ This analytic is to detect a suspicious modification of the active setup registr - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-28 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: f64579c0-203f-11ec-abcc-acde48001122 @@ -47,10 +47,15 @@ This analytic is to detect a suspicious modification of the active setup registr ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_value_name = "StubPath" Registry.registry_key_name = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_value_name= "StubPath" Registry.registry_path = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `active_setup_registry_autostart_filter` ``` @@ -103,4 +108,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/active_setup_registry_autostart.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/active_setup_registry_autostart.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md b/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md similarity index 73% rename from docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md rename to docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md index c510f5e1b4..3b9666b5f5 100644 --- a/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md +++ b/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md @@ -3,7 +3,7 @@ title: "Add DefaultUser And Password In Registry" excerpt: "Credentials in Registry, Unsecured Credentials" categories: - Endpoint -last_modified_at: 2021-09-06 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ this search is to detect a suspicious registry modification to implement auto ad - **Type**: Anomaly - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-06 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: d4a3eb62-0f1e-11ec-a971-acde48001122 @@ -45,10 +45,15 @@ this search is to detect a suspicious registry modification to implement auto ad ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_value_data Registry.registry_key_name | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `add_defaultuser_and_password_in_registry_filter` ``` @@ -98,4 +103,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md b/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md similarity index 72% rename from docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md rename to docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md index b5a0e523c6..bff6c15ec0 100644 --- a/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md +++ b/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md @@ -3,7 +3,7 @@ title: "Allow Inbound Traffic By Firewall Rule Registry" excerpt: "Remote Desktop Protocol, Remote Services" categories: - Endpoint -last_modified_at: 2021-05-26 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This analytic detects a potential suspicious modification of firewall rule regis - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-26 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: 0a46537c-be02-11eb-92ca-acde48001122 @@ -45,17 +45,22 @@ This analytic detects a potential suspicious modification of firewall rule regis ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_name = "* +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_data = "* |Action=Allow -|*" Registry.registry_value_name = "* +|*" Registry.registry_value_data = "* |Dir=In -|*" Registry.registry_value_name = "* +|*" Registry.registry_value_data = "* |Profile=Public -|*" Registry.registry_value_name = "* -|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user Registry.registry_value_name Registry.dest +|*" Registry.registry_value_data = "* +|LPort=*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `allow_inbound_traffic_by_firewall_rule_registry_filter` ``` @@ -106,4 +111,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-allow_operation_with_consent_admin.md b/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md similarity index 73% rename from docs/_posts/2021-06-10-allow_operation_with_consent_admin.md rename to docs/_posts/2022-01-26-allow_operation_with_consent_admin.md index 669bffed12..674cda4758 100644 --- a/docs/_posts/2021-06-10-allow_operation_with_consent_admin.md +++ b/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md @@ -3,7 +3,7 @@ title: "Allow Operation with Consent Admin" excerpt: "Abuse Elevation Control Mechanism" categories: - Endpoint -last_modified_at: 2021-06-10 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -27,7 +27,7 @@ This analytic identifies a potential privilege escalation attempt to perform mal - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-10 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: 7de17d7a-c9d8-11eb-a812-acde48001122 @@ -42,10 +42,15 @@ This analytic identifies a potential privilege escalation attempt to perform mal ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `allow_operation_with_consent_admin_filter` ``` @@ -96,4 +101,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_operation_with_consent_admin.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/allow_operation_with_consent_admin.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-22-disable_amsi_through_registry.md b/docs/_posts/2022-01-26-disable_amsi_through_registry.md similarity index 78% rename from docs/_posts/2021-06-22-disable_amsi_through_registry.md rename to docs/_posts/2022-01-26-disable_amsi_through_registry.md index 1cec33a1da..c16e0a09d8 100644 --- a/docs/_posts/2021-06-22-disable_amsi_through_registry.md +++ b/docs/_posts/2022-01-26-disable_amsi_through_registry.md @@ -3,7 +3,7 @@ title: "Disable AMSI Through Registry" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-06-22 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ this search is to identify modification in registry to disable AMSI windows feat - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-22 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: 9c27ec42-d338-11eb-9044-acde48001122 @@ -45,10 +45,15 @@ this search is to identify modification in registry to disable AMSI windows feat ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_amsi_through_registry_filter` ``` @@ -94,4 +99,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_amsi_through_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_amsi_through_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-18-disable_defender_antivirus_registry.md b/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md similarity index 73% rename from docs/_posts/2021-10-18-disable_defender_antivirus_registry.md rename to docs/_posts/2022-01-26-disable_defender_antivirus_registry.md index f96b8ad926..3ae5ee2a6b 100644 --- a/docs/_posts/2021-10-18-disable_defender_antivirus_registry.md +++ b/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md @@ -3,7 +3,7 @@ title: "Disable Defender AntiVirus Registry" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-18 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This particular behavior is typically executed when an adversaries or malware ga - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-18 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: aa4f695a-3024-11ec-9987-acde48001122 @@ -45,10 +45,15 @@ This particular behavior is typically executed when an adversaries or malware ga ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name = DisableAntiVirus Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name = DisableAntiVirus Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_antivirus_registry_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_antivirus_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_antivirus_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-18-disable_defender_blockatfirstseen_feature.md b/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md similarity index 72% rename from docs/_posts/2021-10-18-disable_defender_blockatfirstseen_feature.md rename to docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md index 70d69e3991..89162eee65 100644 --- a/docs/_posts/2021-10-18-disable_defender_blockatfirstseen_feature.md +++ b/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md @@ -3,7 +3,7 @@ title: "Disable Defender BlockAtFirstSeen Feature" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-18 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This analytic is to detect a suspicious modification of registry to disable wind - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-18 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras - **ID**: 2dd719ac-3021-11ec-97b4-acde48001122 @@ -45,10 +45,15 @@ This analytic is to detect a suspicious modification of registry to disable wind ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_blockatfirstseen_feature_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-18-disable_defender_enhanced_notification.md b/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md similarity index 72% rename from docs/_posts/2021-10-18-disable_defender_enhanced_notification.md rename to docs/_posts/2022-01-26-disable_defender_enhanced_notification.md index b1440022b5..b08767b890 100644 --- a/docs/_posts/2021-10-18-disable_defender_enhanced_notification.md +++ b/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md @@ -3,7 +3,7 @@ title: "Disable Defender Enhanced Notification" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-18 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This analytic is to detect a suspicious modification of registry to disable wind - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-18 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: dc65678c-301f-11ec-8e30-acde48001122 @@ -45,10 +45,15 @@ This analytic is to detect a suspicious modification of registry to disable wind ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*Microsoft\\Windows Defender\\Reporting*" Registry.registry_value_name = DisableEnhancedNotifications Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*Microsoft\\Windows Defender\\Reporting*" Registry.registry_value_name = DisableEnhancedNotifications Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_enhanced_notification_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_enhanced_notification.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_enhanced_notification.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-18-disable_defender_mpengine_registry.md b/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md similarity index 73% rename from docs/_posts/2021-10-18-disable_defender_mpengine_registry.md rename to docs/_posts/2022-01-26-disable_defender_mpengine_registry.md index 60688c5183..197bdb8958 100644 --- a/docs/_posts/2021-10-18-disable_defender_mpengine_registry.md +++ b/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md @@ -3,7 +3,7 @@ title: "Disable Defender MpEngine Registry" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-18 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This particular behavior is typically executed when an adversaries or malware ga - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-18 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: cc391750-3024-11ec-955a-acde48001122 @@ -45,10 +45,15 @@ This particular behavior is typically executed when an adversaries or malware ga ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_mpengine_registry_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_mpengine_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_mpengine_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-18-disable_defender_spynet_reporting.md b/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md similarity index 72% rename from docs/_posts/2021-10-18-disable_defender_spynet_reporting.md rename to docs/_posts/2022-01-26-disable_defender_spynet_reporting.md index 4ab86b2244..e39ab1b30d 100644 --- a/docs/_posts/2021-10-18-disable_defender_spynet_reporting.md +++ b/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md @@ -3,7 +3,7 @@ title: "Disable Defender Spynet Reporting" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-18 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This analytic is to detect a suspicious modification of registry to disable wind - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-18 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: 898debf4-3021-11ec-ba7c-acde48001122 @@ -45,10 +45,15 @@ This analytic is to detect a suspicious modification of registry to disable wind ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SpynetReporting Registry.registry_value_data = 0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SpynetReporting Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_spynet_reporting_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_spynet_reporting.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_spynet_reporting.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-18-disable_defender_submit_samples_consent_feature.md b/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md similarity index 72% rename from docs/_posts/2021-10-18-disable_defender_submit_samples_consent_feature.md rename to docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md index e08e83da1c..346e51a714 100644 --- a/docs/_posts/2021-10-18-disable_defender_submit_samples_consent_feature.md +++ b/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md @@ -3,7 +3,7 @@ title: "Disable Defender Submit Samples Consent Feature" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-18 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ his analytic is to detect a suspicious modification of registry to disable windo - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-18 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: 73922ff8-3022-11ec-bf5e-acde48001122 @@ -45,10 +45,15 @@ his analytic is to detect a suspicious modification of registry to disable windo ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SubmitSamplesConsent Registry.registry_value_data = 0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SubmitSamplesConsent Registry.registry_value_data = 0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_defender_submit_samples_consent_feature_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md b/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md similarity index 59% rename from docs/_posts/2021-09-07-registry_keys_used_for_persistence.md rename to docs/_posts/2022-01-26-registry_keys_used_for_persistence.md index ec4585210c..448f10ee78 100644 --- a/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md +++ b/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md @@ -3,7 +3,7 @@ title: "Registry Keys Used For Persistence" excerpt: "Registry Run Keys / Startup Folder, Boot or Logon Autostart Execution" categories: - Endpoint -last_modified_at: 2021-09-07 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -30,8 +30,8 @@ The search looks for modifications to registry keys that can be used to launch a - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-07 -- **Author**: Jose Hernandez, David Dorsey, Splunk +- **Last Updated**: 2022-01-26 +- **Author**: Jose Hernandez, David Dorsey, Teoderick Contreras, Splunk - **ID**: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b @@ -47,10 +47,15 @@ The search looks for modifications to registry keys that can be used to launch a ``` -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `registry_keys_used_for_persistence_filter` ``` @@ -105,4 +110,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_persistence.yml) \| *version*: **6** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_persistence.yml) \| *version*: **7** \ No newline at end of file diff --git a/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md b/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md similarity index 73% rename from docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md rename to docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md index 6dd6696d2d..1d0e3b7e35 100644 --- a/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md +++ b/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md @@ -3,7 +3,7 @@ title: "Registry Keys Used For Privilege Escalation" excerpt: "Image File Execution Options Injection, Event Triggered Execution" categories: - Endpoint -last_modified_at: 2020-11-27 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -29,8 +29,8 @@ This search looks for modifications to registry keys that can be used to elevate - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: -- **Last Updated**: 2020-11-27 -- **Author**: David Dorsey, Splunk +- **Last Updated**: 2022-01-26 +- **Author**: David Dorsey, Teoderick Contreras, Splunk - **ID**: c9f4b923-f8af-4155-b697-1354f5bcbc5e @@ -46,10 +46,15 @@ This search looks for modifications to registry keys that can be used to elevate ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger) by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `registry_keys_used_for_privilege_escalation_filter` ``` @@ -101,4 +106,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml) \| *version*: **4** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml) \| *version*: **5** \ No newline at end of file diff --git a/docs/_posts/2021-09-24-remcos_client_registry_install_entry.md b/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md similarity index 71% rename from docs/_posts/2021-09-24-remcos_client_registry_install_entry.md rename to docs/_posts/2022-01-26-remcos_client_registry_install_entry.md index 93a1854c3e..79aa9ea9c6 100644 --- a/docs/_posts/2021-09-24-remcos_client_registry_install_entry.md +++ b/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md @@ -3,7 +3,7 @@ title: "Remcos client registry install entry" excerpt: "Modify Registry" categories: - Endpoint -last_modified_at: 2021-09-24 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -26,8 +26,8 @@ This search detects registry key license at host where Remcos RAT agent is insta - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-24 -- **Author**: Bhavin Patel, Rod Soto, Splunk +- **Last Updated**: 2022-01-26 +- **Author**: Bhavin Patel, Rod Soto, Teoderick Contreras, Splunk - **ID**: f2a1615a-1d63-11ec-97d2-acde48001122 @@ -41,10 +41,15 @@ This search detects registry key license at host where Remcos RAT agent is insta ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Registry.registry_path) as registry_path FROM datamodel=Endpoint.Registry where (Registry.registry_key_name=*\\Software\\Remcos*) by Registry.dest Registry.user Registry.registry_key_name Registry.process_id +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where (Registry.registry_key_name=*\\Software\\Remcos*) by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data |`remcos_client_registry_install_entry_filter` ``` @@ -95,4 +100,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remcos_client_registry_install_entry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/remcos_client_registry_install_entry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md b/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md similarity index 76% rename from docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md rename to docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md index 10b2f162f9..ef5f1cc794 100644 --- a/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md +++ b/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md @@ -3,7 +3,7 @@ title: "Start Up During Safe Mode Boot" excerpt: "Registry Run Keys / Startup Folder, Boot or Logon Autostart Execution" categories: - Endpoint -last_modified_at: 2021-06-10 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -30,7 +30,7 @@ This search is to detect a modification or registry add to the safeboot registry - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-10 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: c6149154-c9d8-11eb-9da7-acde48001122 @@ -47,10 +47,15 @@ This search is to detect a modification or registry add to the safeboot registry ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `start_up_during_safe_mode_boot_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/start_up_during_safe_mode_boot.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/start_up_during_safe_mode_boot.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-29-time_provider_persistence_registry.md b/docs/_posts/2022-01-26-time_provider_persistence_registry.md similarity index 72% rename from docs/_posts/2021-09-29-time_provider_persistence_registry.md rename to docs/_posts/2022-01-26-time_provider_persistence_registry.md index 31f952d356..8d7d2d86fc 100644 --- a/docs/_posts/2021-09-29-time_provider_persistence_registry.md +++ b/docs/_posts/2022-01-26-time_provider_persistence_registry.md @@ -3,7 +3,7 @@ title: "Time Provider Persistence Registry" excerpt: "Time Providers, Boot or Logon Autostart Execution" categories: - Endpoint -last_modified_at: 2021-09-29 +last_modified_at: 2022-01-26 toc: true toc_label: "" tags: @@ -25,12 +25,12 @@ tags: #### Description -This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. +This analytic is to detect a suspicious modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-29 +- **Last Updated**: 2022-01-26 - **Author**: Teoderick Contreras, Splunk - **ID**: 5ba382c4-2105-11ec-8d8f-acde48001122 @@ -47,10 +47,15 @@ This analytic is to detect a suspiciouos modification of time provider registry ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `time_provider_persistence_registry_filter` ``` @@ -103,4 +108,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/time_provider_persistence_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/time_provider_persistence_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-22-disable_etw_through_registry.md b/docs/_posts/2022-01-27-disable_etw_through_registry.md similarity index 72% rename from docs/_posts/2021-06-22-disable_etw_through_registry.md rename to docs/_posts/2022-01-27-disable_etw_through_registry.md index dd0b6e0d16..7ac607c7ff 100644 --- a/docs/_posts/2021-06-22-disable_etw_through_registry.md +++ b/docs/_posts/2022-01-27-disable_etw_through_registry.md @@ -3,7 +3,7 @@ title: "Disable ETW Through Registry" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-06-22 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ this search is to identify modification in registry to disable ETW windows featu - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-06-22 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: f0eacfa4-d33f-11eb-8f9d-acde48001122 @@ -45,10 +45,15 @@ this search is to identify modification in registry to disable ETW windows featu ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_etw_through_registry_filter` ``` @@ -93,4 +98,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_etw_through_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_etw_through_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disable_registry_tool.md b/docs/_posts/2022-01-27-disable_registry_tool.md similarity index 78% rename from docs/_posts/2021-03-31-disable_registry_tool.md rename to docs/_posts/2022-01-27-disable_registry_tool.md index 4f539149ba..4da9714634 100644 --- a/docs/_posts/2021-03-31-disable_registry_tool.md +++ b/docs/_posts/2022-01-27-disable_registry_tool.md @@ -3,7 +3,7 @@ title: "Disable Registry Tool" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This search identifies modification of registry to disable the regedit or regist - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: cd2cf33c-9201-11eb-a10a-acde48001122 @@ -45,10 +45,15 @@ This search identifies modification of registry to disable the regedit or regist ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_registry_tool_filter` ``` @@ -101,4 +106,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_registry_tool.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_registry_tool.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md b/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md similarity index 74% rename from docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md rename to docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md index e0d237e5b5..eff7922b0b 100644 --- a/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md +++ b/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md @@ -3,7 +3,7 @@ title: "Disable Security Logs Using MiniNt Registry" excerpt: "Modify Registry" categories: - Endpoint -last_modified_at: 2021-10-05 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -26,7 +26,7 @@ This analytic is to detect a suspicious registry modification to disable securit - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-05 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: 39ebdc68-25b9-11ec-aec7-acde48001122 @@ -41,9 +41,15 @@ This analytic is to detect a suspicious registry modification to disable securit ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid +| `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_security_logs_using_minint_registry_filter` ``` @@ -95,4 +101,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_security_logs_using_minint_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_security_logs_using_minint_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disable_show_hidden_files.md b/docs/_posts/2022-01-27-disable_show_hidden_files.md similarity index 75% rename from docs/_posts/2021-03-31-disable_show_hidden_files.md rename to docs/_posts/2022-01-27-disable_show_hidden_files.md index 60ac56d81a..7787737651 100644 --- a/docs/_posts/2021-03-31-disable_show_hidden_files.md +++ b/docs/_posts/2022-01-27-disable_show_hidden_files.md @@ -3,7 +3,7 @@ title: "Disable Show Hidden Files" excerpt: "Hidden Files and Directories, Disable or Modify Tools, Hide Artifacts, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -32,7 +32,7 @@ The following analytic is to identify a modification in the Windows registry to - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Mauricio Velazco, Splunk - **ID**: 6f3ccfa2-91fe-11eb-8f9b-acde48001122 @@ -53,10 +53,15 @@ The following analytic is to identify a modification in the Windows registry to ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_data = "0x00000000") by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_data = "0x00000000") by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_show_hidden_files_filter` ``` @@ -109,4 +114,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_show_hidden_files.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_show_hidden_files.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-09-29-disable_uac_remote_restriction.md b/docs/_posts/2022-01-27-disable_uac_remote_restriction.md similarity index 78% rename from docs/_posts/2021-09-29-disable_uac_remote_restriction.md rename to docs/_posts/2022-01-27-disable_uac_remote_restriction.md index a91bf2bc5b..8687ec54f8 100644 --- a/docs/_posts/2021-09-29-disable_uac_remote_restriction.md +++ b/docs/_posts/2022-01-27-disable_uac_remote_restriction.md @@ -3,7 +3,7 @@ title: "Disable UAC Remote Restriction" excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint -last_modified_at: 2021-09-29 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -30,7 +30,7 @@ This analytic is to detect a suspicious modification of registry to disable UAC - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-09-29 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: 9928b732-210e-11ec-b65e-acde48001122 @@ -47,10 +47,15 @@ This analytic is to detect a suspicious modification of registry to disable UAC ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_uac_remote_restriction_filter` ``` @@ -103,4 +108,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_uac_remote_restriction.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_uac_remote_restriction.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md b/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md similarity index 73% rename from docs/_posts/2021-05-05-disable_windows_app_hotkeys.md rename to docs/_posts/2022-01-27-disable_windows_app_hotkeys.md index 88f77eb9fb..91459be955 100644 --- a/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md +++ b/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md @@ -3,7 +3,7 @@ title: "Disable Windows App Hotkeys" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-05-05 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This analytic detects a suspicious registry modification to disable Windows hotk - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-05 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: 1490f224-ad8b-11eb-8c4f-acde48001122 @@ -45,10 +45,15 @@ This analytic detects a suspicious registry modification to disable Windows hotk ``` -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_name = "HotKey Disabled" AND Registry.registry_key_name = "Debugger" by Registry.dest Registry.user Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_data= "HotKey Disabled" AND Registry.registry_value_name = "Debugger" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disable_windows_app_hotkeys_filter` ``` @@ -98,4 +103,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_app_hotkeys.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_app_hotkeys.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md b/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md similarity index 69% rename from docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md rename to docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md index a7d3d0146b..8c6877c7a8 100644 --- a/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md +++ b/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md @@ -3,7 +3,7 @@ title: "Disable Windows Behavior Monitoring" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This search is to identifies a modification in registry to disable the windows d - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: 79439cae-9200-11eb-a4d3-acde48001122 @@ -45,10 +45,15 @@ This search is to identifies a modification in registry to disable the windows d ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" AND Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_windows_behavior_monitoring_filter` ``` @@ -103,4 +108,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_behavior_monitoring.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_behavior_monitoring.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md b/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md similarity index 77% rename from docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md rename to docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md index 766f902e8c..21b69a778a 100644 --- a/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md +++ b/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md @@ -3,7 +3,7 @@ title: "Disable Windows SmartScreen Protection" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ The following search identifies a modification of registry to disable the smarts - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: 664f0fd0-91ff-11eb-a56f-acde48001122 @@ -45,10 +45,15 @@ The following search identifies a modification of registry to disable the smarts ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_name = "Off" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_data= "Off" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disable_windows_smartscreen_protection_filter` ``` @@ -101,4 +106,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_smartscreen_protection.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_windows_smartscreen_protection.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disabling_cmd_application.md b/docs/_posts/2022-01-27-disabling_cmd_application.md similarity index 77% rename from docs/_posts/2021-03-31-disabling_cmd_application.md rename to docs/_posts/2022-01-27-disabling_cmd_application.md index 5bda9b7965..25c72c2ef3 100644 --- a/docs/_posts/2021-03-31-disabling_cmd_application.md +++ b/docs/_posts/2022-01-27-disabling_cmd_application.md @@ -3,7 +3,7 @@ title: "Disabling CMD Application" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ this search is to identify modification in registry to disable cmd prompt applic - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: ff86077c-9212-11eb-a1e6-acde48001122 @@ -45,10 +45,15 @@ this search is to identify modification in registry to disable cmd prompt applic ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_cmd_application_filter` ``` @@ -101,4 +106,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_cmd_application.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_cmd_application.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disabling_controlpanel.md b/docs/_posts/2022-01-27-disabling_controlpanel.md similarity index 76% rename from docs/_posts/2021-03-31-disabling_controlpanel.md rename to docs/_posts/2022-01-27-disabling_controlpanel.md index ddb6b3e77e..c2f98a5340 100644 --- a/docs/_posts/2021-03-31-disabling_controlpanel.md +++ b/docs/_posts/2022-01-27-disabling_controlpanel.md @@ -3,7 +3,7 @@ title: "Disabling ControlPanel" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ this search is to identify registry modification to disable control panel window - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-27 - **Author**: Teoderick Contreras, Splunk - **ID**: 6ae0148e-9215-11eb-a94a-acde48001122 @@ -45,10 +45,15 @@ this search is to identify registry modification to disable control panel window ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_controlpanel_filter` ``` @@ -101,4 +106,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_controlpanel.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_controlpanel.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2022-01-10-windows_possible_credential_dumping.md b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md similarity index 92% rename from docs/_posts/2022-01-10-windows_possible_credential_dumping.md rename to docs/_posts/2022-01-27-windows_possible_credential_dumping.md index 950eb229fe..8a66a573eb 100644 --- a/docs/_posts/2022-01-10-windows_possible_credential_dumping.md +++ b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md @@ -3,7 +3,7 @@ title: "Windows Possible Credential Dumping" excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint -last_modified_at: 2022-01-10 +last_modified_at: 2022-01-27 toc: true toc_label: "" tags: @@ -31,7 +31,7 @@ The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll. - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: -- **Last Updated**: 2022-01-10 +- **Last Updated**: 2022-01-27 - **Author**: Michael Haag, Splunk - **ID**: e4723b92-7266-11ec-af45-acde48001122 @@ -47,7 +47,7 @@ The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll. #### Search ``` -`sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess IN ("0x01000", "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x1438", "0x143a", "0x1438", "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") +`sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess IN ("0x01000", "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438", "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") | stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser | rename Computer as dest | `security_content_ctime(firstTime)` @@ -80,7 +80,7 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Known False Positives -False positives will occur based on GrantedAccess, filter based on source image as needed. +False positives will occur based on GrantedAccess 0x1010 and 0x1400, filter based on source image as needed or remove them. Concern is Cobalt Strike usage of Mimikatz will generate 0x1010 initially, but later be caught. #### RBA @@ -110,4 +110,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_possible_credential_dumping.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_possible_credential_dumping.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-20-disabling_defender_services.md b/docs/_posts/2022-01-28-disabling_defender_services.md similarity index 71% rename from docs/_posts/2021-10-20-disabling_defender_services.md rename to docs/_posts/2022-01-28-disabling_defender_services.md index e30bcb3daf..1afb6c0473 100644 --- a/docs/_posts/2021-10-20-disabling_defender_services.md +++ b/docs/_posts/2022-01-28-disabling_defender_services.md @@ -3,7 +3,7 @@ title: "Disabling Defender Services" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-20 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This particular behavior is typically executed when an adversaries or malware ga - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-20 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: 911eacdc-317f-11ec-ad30-acde48001122 @@ -45,10 +45,15 @@ This particular behavior is typically executed when an adversaries or malware ga ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*", "*WinDefend*", "*SecurityHealthService*")) AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*","*WinDefend*", "*SecurityHealthService*")) AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data | `disabling_defender_services_filter` ``` @@ -100,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_defender_services.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_defender_services.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md b/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md similarity index 77% rename from docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md rename to docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md index 4fb59ae1be..b7550b7616 100644 --- a/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md +++ b/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md @@ -3,7 +3,7 @@ title: "Disabling FolderOptions Windows Feature" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This search is to identify registry modification to disable folder options featu - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: 83776de4-921a-11eb-868a-acde48001122 @@ -45,10 +45,15 @@ This search is to identify registry modification to disable folder options featu ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_folderoptions_windows_feature_filter` ``` @@ -101,4 +106,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disabling_norun_windows_app.md b/docs/_posts/2022-01-28-disabling_norun_windows_app.md similarity index 78% rename from docs/_posts/2021-03-31-disabling_norun_windows_app.md rename to docs/_posts/2022-01-28-disabling_norun_windows_app.md index 5e02775a0f..912855f1ce 100644 --- a/docs/_posts/2021-03-31-disabling_norun_windows_app.md +++ b/docs/_posts/2022-01-28-disabling_norun_windows_app.md @@ -3,7 +3,7 @@ title: "Disabling NoRun Windows App" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This search is to identify modification of registry to disable run application i - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: de81bc46-9213-11eb-adc9-acde48001122 @@ -45,10 +45,15 @@ This search is to identify modification of registry to disable run application i ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_norun_windows_app_filter` ``` @@ -102,4 +107,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_norun_windows_app.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_norun_windows_app.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md b/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md similarity index 74% rename from docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md rename to docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md index c3a1d6ddc2..917c61115c 100644 --- a/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md +++ b/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md @@ -3,7 +3,7 @@ title: "Disabling SystemRestore In Registry" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ The following search identifies the modification of registry related in disablin - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: f4f837e2-91fb-11eb-8bf6-acde48001122 @@ -45,10 +45,15 @@ The following search identifies the modification of registry related in disablin ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_systemrestore_in_registry_filter` ``` @@ -101,4 +106,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_systemrestore_in_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_systemrestore_in_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-31-disabling_task_manager.md b/docs/_posts/2022-01-28-disabling_task_manager.md similarity index 77% rename from docs/_posts/2021-03-31-disabling_task_manager.md rename to docs/_posts/2022-01-28-disabling_task_manager.md index b6183c6b0a..6a1a9c7030 100644 --- a/docs/_posts/2021-03-31-disabling_task_manager.md +++ b/docs/_posts/2022-01-28-disabling_task_manager.md @@ -3,7 +3,7 @@ title: "Disabling Task Manager" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-03-31 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This search is to identifies modification of registry to disable the task manage - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-31 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: dac279bc-9202-11eb-b7fb-acde48001122 @@ -45,10 +45,15 @@ This search is to identifies modification of registry to disable the task manage ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest +| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.process_guid Registry.registry_value_data | `drop_dm_object_name(Registry)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `disabling_task_manager_filter` ``` @@ -102,4 +107,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_task_manager.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disabling_task_manager.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-19-enable_rdp_in_other_port_number.md b/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md similarity index 70% rename from docs/_posts/2021-05-19-enable_rdp_in_other_port_number.md rename to docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md index 2ffc0e0583..64c150f729 100644 --- a/docs/_posts/2021-05-19-enable_rdp_in_other_port_number.md +++ b/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md @@ -3,7 +3,7 @@ title: "Enable RDP In Other Port Number" excerpt: "Remote Services" categories: - Endpoint -last_modified_at: 2021-05-19 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -26,7 +26,7 @@ This search is to detect a modification to registry to enable rdp to a machine w - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-19 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: 99495452-b899-11eb-96dc-acde48001122 @@ -41,10 +41,15 @@ This search is to detect a modification to registry to enable rdp to a machine w ``` -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber" by Registry.dest Registry.user Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `enable_rdp_in_other_port_number_filter` ``` @@ -94,4 +99,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enable_rdp_in_other_port_number.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enable_rdp_in_other_port_number.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md b/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md similarity index 78% rename from docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md rename to docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md index cd1eff5595..ccc89dd7b3 100644 --- a/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md +++ b/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md @@ -3,7 +3,7 @@ title: "Enable WDigest UseLogonCredential Registry" excerpt: "Modify Registry, OS Credential Dumping" categories: - Endpoint -last_modified_at: 2021-10-05 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This analytic is to detect a suspicious registry modification to enable plain te - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-05 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: 0c7d8ffe-25b1-11ec-9f39-acde48001122 @@ -45,9 +45,15 @@ This analytic is to detect a suspicious registry modification to enable plain te ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data +| `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `enable_wdigest_uselogoncredential_registry_filter` ``` @@ -99,4 +105,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-07-etw_registry_disabled.md b/docs/_posts/2022-01-28-etw_registry_disabled.md similarity index 75% rename from docs/_posts/2021-10-07-etw_registry_disabled.md rename to docs/_posts/2022-01-28-etw_registry_disabled.md index ea93be473c..af2975e942 100644 --- a/docs/_posts/2021-10-07-etw_registry_disabled.md +++ b/docs/_posts/2022-01-28-etw_registry_disabled.md @@ -3,7 +3,7 @@ title: "ETW Registry Disabled" excerpt: "Indicator Blocking, Trusted Developer Utilities Proxy Execution, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-10-07 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -30,7 +30,7 @@ This analytic is to detect a registry modification to disable ETW feature of win - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-10-07 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: 8ed523ac-276b-11ec-ac39-acde48001122 @@ -49,9 +49,15 @@ This analytic is to detect a registry modification to disable ETW feature of win ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*") Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*" Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data +| `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `etw_registry_disabled_filter` ``` @@ -104,4 +110,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/etw_registry_disabled.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/etw_registry_disabled.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-03-01-eventvwr_uac_bypass.md b/docs/_posts/2022-01-28-eventvwr_uac_bypass.md similarity index 81% rename from docs/_posts/2021-03-01-eventvwr_uac_bypass.md rename to docs/_posts/2022-01-28-eventvwr_uac_bypass.md index c8e5e18ce3..ec6fb827d9 100644 --- a/docs/_posts/2021-03-01-eventvwr_uac_bypass.md +++ b/docs/_posts/2022-01-28-eventvwr_uac_bypass.md @@ -3,7 +3,7 @@ title: "Eventvwr UAC Bypass" excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint -last_modified_at: 2021-03-01 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -30,7 +30,7 @@ The following search identifies Eventvwr bypass by identifying the registry modi - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-03-01 +- **Last Updated**: 2022-01-28 - **Author**: Michael Haag, Splunk - **ID**: 9cf8fe08-7ad8-11eb-9819-acde48001122 @@ -47,10 +47,15 @@ The following search identifies Eventvwr bypass by identifying the registry modi ``` -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by Registry.user, Registry.dest , Registry.registry_value_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `eventvwr_uac_bypass_filter` ``` @@ -106,4 +111,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/eventvwr_uac_bypass.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/eventvwr_uac_bypass.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md b/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md similarity index 73% rename from docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md rename to docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md index 4336c1114b..0bc53360b9 100644 --- a/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md +++ b/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md @@ -3,7 +3,7 @@ title: "Hide User Account From Sign-In Screen" excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint -last_modified_at: 2021-05-05 +last_modified_at: 2022-01-28 toc: true toc_label: "" tags: @@ -28,7 +28,7 @@ This analytic identifies a suspicious registry modification to hide a user accou - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) -- **Last Updated**: 2021-05-05 +- **Last Updated**: 2022-01-28 - **Author**: Teoderick Contreras, Splunk - **ID**: 834ba832-ad89-11eb-937d-acde48001122 @@ -45,10 +45,15 @@ This analytic identifies a suspicious registry modification to hide a user accou ``` -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data = "0x00000000" by Registry.dest Registry.user Registry.registry_value_data -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data = "0x00000000" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)` +|rename process_guid as proc_guid +|join proc_guid, _time [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid +| `drop_dm_object_name(Processes)` +|rename process_guid as proc_guid +| fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name] +| table _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name | `hide_user_account_from_sign_in_screen_filter` ``` @@ -98,4 +103,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/hide_user_account_from_sign-in_screen.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/hide_user_account_from_sign-in_screen.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/information_sabotage.md b/docs/_stories/information_sabotage.md index 8aed539171..fb16a287a3 100644 --- a/docs/_stories/information_sabotage.md +++ b/docs/_stories/information_sabotage.md @@ -32,6 +32,8 @@ Information sabotage is the type of crime many people associate with insider thr | Name | Technique | Type | | ----------- | ----------- |--------------| +| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [High Frequency Copy Of Files In Network Share](/endpoint/high_frequency_copy_of_files_in_network_share/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | Anomaly | | [Sdelete Application Execution](/endpoint/sdelete_application_execution/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | Anomaly | diff --git a/docs/_stories/ransomware.md b/docs/_stories/ransomware.md index ff443e2e0f..9a49195d23 100644 --- a/docs/_stories/ransomware.md +++ b/docs/_stories/ransomware.md @@ -42,6 +42,7 @@ Ransomware is an ever-present risk to the enterprise, wherein an infected host e | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Conti Common Exec parameter](/endpoint/conti_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | diff --git a/docs/_stories/suspicious_command-line_executions.md b/docs/_stories/suspicious_command-line_executions.md index 699fcc8a30..45fab7943b 100644 --- a/docs/_stories/suspicious_command-line_executions.md +++ b/docs/_stories/suspicious_command-line_executions.md @@ -34,6 +34,7 @@ The ability to execute arbitrary commands via the Windows CLI is a primary goal | [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | Hunting | | [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Anomaly | | [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | TTP | +| [Potentially malicious code on commandline](/endpoint/potentially_malicious_code_on_commandline/) | [Windows Command Shell](/tags/#windows-command-shell) | Anomaly | | [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | | [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | | Anomaly | | [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | | Anomaly | diff --git a/docs/_stories/windows_defense_evasion_tactics.md b/docs/_stories/windows_defense_evasion_tactics.md index 40cc14f704..670239b265 100644 --- a/docs/_stories/windows_defense_evasion_tactics.md +++ b/docs/_stories/windows_defense_evasion_tactics.md @@ -52,6 +52,7 @@ Defense evasion is a tactic--identified in the MITRE ATT&CK framework--that adve | [Firewall Allowed Program Enable](/endpoint/firewall_allowed_program_enable/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Powershell Windows Defender Exclusion Commands](/endpoint/powershell_windows_defender_exclusion_commands/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | diff --git a/docs/_stories/windows_persistence_techniques.md b/docs/_stories/windows_persistence_techniques.md index 2ac45b788a..b40b5b83ea 100644 --- a/docs/_stories/windows_persistence_techniques.md +++ b/docs/_stories/windows_persistence_techniques.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -17,7 +18,7 @@ tags: Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) - **Last Updated**: 2018-05-31 - **Author**: Bhavin Patel, Splunk - **ID**: 30874d4f-20a1-488f-85ec-5d52ef74e3f9 @@ -36,6 +37,7 @@ Maintaining persistence is one of the first steps taken by attackers after the i | [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | | [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | TTP | | [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | diff --git a/docs/index.markdown b/docs/index.markdown index 124a413900..3e11bdf01e 100644 --- a/docs/index.markdown +++ b/docs/index.markdown @@ -9,12 +9,12 @@ header: actions: - label: "Download" url: "https://splunkbase.splunk.com/app/3449/" -excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **745** detections for Splunk." +excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **750** detections for Splunk." feature_row: - image_path: /static/feature_detection.png alt: "customizable" title: "Detections" - excerpt: "See all **745** Splunk Analytics built to find evil 😈." + excerpt: "See all **750** Splunk Analytics built to find evil 😈." url: "/detections" btn_class: "btn--primary" btn_label: "Explore" diff --git a/docs/mitre-map/coverage.csv b/docs/mitre-map/coverage.csv index 4046261f51..28c4f4c368 100644 --- a/docs/mitre-map/coverage.csv +++ b/docs/mitre-map/coverage.csv @@ -298,41 +298,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -396,43 +396,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -530,7 +531,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -700,16 +702,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -812,51 +815,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -1232,22 +1236,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -1346,13 +1351,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -1504,10 +1510,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -2110,41 +2117,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -2208,43 +2215,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -2342,7 +2350,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -2512,16 +2521,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -2624,51 +2634,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -3044,22 +3055,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -3158,13 +3170,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -3316,10 +3329,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -3922,41 +3936,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -4020,43 +4034,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -4154,7 +4169,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -4324,16 +4340,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -4436,51 +4453,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -4856,22 +4874,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -4970,13 +4989,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -5128,10 +5148,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -5734,41 +5755,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -5832,43 +5853,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -5966,7 +5988,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -6136,16 +6159,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -6248,51 +6272,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -6668,22 +6693,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -6782,13 +6808,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -6940,10 +6967,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -7546,41 +7574,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -7644,43 +7672,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -7778,7 +7807,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -7948,16 +7978,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -8060,51 +8091,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -8480,22 +8512,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -8594,13 +8627,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -8752,10 +8786,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -9358,41 +9393,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -9456,43 +9491,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -9590,7 +9626,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -9760,16 +9797,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -9872,51 +9910,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -10292,22 +10331,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -10406,13 +10446,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -10564,10 +10605,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -11170,41 +11212,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -11268,43 +11310,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -11402,7 +11445,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -11572,16 +11616,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -11684,51 +11729,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -12104,22 +12150,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -12218,13 +12265,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -12376,10 +12424,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -12982,41 +13031,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -13080,43 +13129,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -13214,7 +13264,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -13384,16 +13435,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -13496,51 +13548,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -13916,22 +13969,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -14030,13 +14084,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -14188,10 +14243,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -14794,41 +14850,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -14892,43 +14948,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -15026,7 +15083,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -15196,16 +15254,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -15308,51 +15367,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -15728,22 +15788,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -15842,13 +15903,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -16000,10 +16062,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -16606,41 +16669,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -16704,43 +16767,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -16838,7 +16902,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -17008,16 +17073,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -17120,51 +17186,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -17540,22 +17607,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -17654,13 +17722,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -17812,10 +17881,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -18418,41 +18488,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -18516,43 +18586,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -18650,7 +18721,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -18820,16 +18892,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -18932,51 +19005,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -19352,22 +19426,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -19466,13 +19541,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -19624,10 +19700,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -20230,41 +20307,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -20328,43 +20405,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -20462,7 +20540,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -20632,16 +20711,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -20744,51 +20824,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -21164,22 +21245,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -21278,13 +21360,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -21436,10 +21519,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -22042,41 +22126,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -22140,43 +22224,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -22274,7 +22359,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -22444,16 +22530,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -22556,51 +22643,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -22976,22 +23064,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -23090,13 +23179,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -23248,10 +23338,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -23854,41 +23945,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -23952,43 +24043,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -24086,7 +24178,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -24256,16 +24349,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -24368,51 +24462,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -24788,22 +24883,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -24902,13 +24998,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -25060,10 +25157,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -25666,41 +25764,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -25764,43 +25862,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -25898,7 +25997,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -26068,16 +26168,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -26180,51 +26281,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -26600,22 +26702,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -26714,13 +26817,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -26872,10 +26976,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -27478,41 +27583,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -27576,43 +27681,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -27710,7 +27816,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -27880,16 +27987,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -27992,51 +28100,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -28412,22 +28521,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -28526,13 +28636,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -28684,10 +28795,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -29290,41 +29402,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -29388,43 +29500,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -29522,7 +29635,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -29692,16 +29806,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -29804,51 +29919,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -30224,22 +30340,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -30338,13 +30455,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -30496,10 +30614,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -31102,41 +31221,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -31200,43 +31319,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -31334,7 +31454,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -31504,16 +31625,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -31616,51 +31738,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -32036,22 +32159,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -32150,13 +32274,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -32308,10 +32433,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -32914,41 +33040,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -33012,43 +33138,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -33146,7 +33273,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -33316,16 +33444,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -33428,51 +33557,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -33848,22 +33978,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -33962,13 +34093,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -34120,10 +34252,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -34726,41 +34859,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -34824,43 +34957,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -34958,7 +35092,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -35128,16 +35263,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -35240,51 +35376,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -35660,22 +35797,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -35774,13 +35912,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -35932,10 +36071,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -36538,41 +36678,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -36636,43 +36776,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -36770,7 +36911,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -36940,16 +37082,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -37052,51 +37195,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -37472,22 +37616,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -37586,13 +37731,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -37744,10 +37890,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -38350,41 +38497,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -38448,43 +38595,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -38582,7 +38730,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -38752,16 +38901,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -38864,51 +39014,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -39284,22 +39435,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -39398,13 +39550,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -39556,10 +39709,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -40162,41 +40316,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -40260,43 +40414,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -40394,7 +40549,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -40564,16 +40720,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -40676,51 +40833,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -41096,22 +41254,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -41210,13 +41369,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -41368,10 +41528,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -41974,41 +42135,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -42072,43 +42233,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -42206,7 +42368,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -42376,16 +42539,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -42488,51 +42652,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -42908,22 +43073,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -43022,13 +43188,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -43180,10 +43347,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -43786,41 +43954,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -43884,43 +44052,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -44018,7 +44187,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -44188,16 +44358,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -44300,51 +44471,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -44720,22 +44892,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -44834,13 +45007,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -44992,10 +45166,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -45598,41 +45773,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -45696,43 +45871,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -45830,7 +46006,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -46000,16 +46177,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -46112,51 +46290,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -46532,22 +46711,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -46646,13 +46826,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -46804,10 +46985,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -47410,41 +47592,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -47508,43 +47690,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -47642,7 +47825,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -47812,16 +47996,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -47924,51 +48109,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -48344,22 +48530,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -48458,13 +48645,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -48616,10 +48804,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -49222,41 +49411,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -49320,43 +49509,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -49454,7 +49644,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -49624,16 +49815,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -49736,51 +49928,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -50156,22 +50349,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -50270,13 +50464,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -50428,10 +50623,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -51034,41 +51230,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -51132,43 +51328,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -51266,7 +51463,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -51436,16 +51634,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -51548,51 +51747,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -51968,22 +52168,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -52082,13 +52283,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -52240,10 +52442,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -52846,41 +53049,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -52944,43 +53147,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -53078,7 +53282,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -53248,16 +53453,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -53360,51 +53566,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -53780,22 +53987,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -53894,13 +54102,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -54052,10 +54261,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -54658,41 +54868,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -54756,43 +54966,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -54890,7 +55101,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -55060,16 +55272,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -55172,51 +55385,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -55592,22 +55806,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -55706,13 +55921,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -55864,10 +56080,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -56470,41 +56687,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -56568,43 +56785,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -56702,7 +56920,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -56872,16 +57091,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -56984,51 +57204,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -57404,22 +57625,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -57518,13 +57740,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -57676,10 +57899,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -58282,41 +58506,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -58380,43 +58604,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -58514,7 +58739,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -58684,16 +58910,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -58796,51 +59023,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -59216,22 +59444,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -59330,13 +59559,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -59488,10 +59718,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -60094,41 +60325,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -60192,43 +60423,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -60326,7 +60558,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -60496,16 +60729,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -60608,51 +60842,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -61028,22 +61263,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -61142,13 +61378,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -61300,10 +61537,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -61906,41 +62144,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -62004,43 +62242,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -62138,7 +62377,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -62308,16 +62548,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -62420,51 +62661,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -62840,22 +63082,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -62954,13 +63197,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -63112,10 +63356,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -63718,41 +63963,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -63816,43 +64061,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -63950,7 +64196,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -64120,16 +64367,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -64232,51 +64480,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -64652,22 +64901,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -64766,13 +65016,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -64924,10 +65175,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -65530,41 +65782,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -65628,43 +65880,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -65762,7 +66015,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -65932,16 +66186,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -66044,51 +66299,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -66464,22 +66720,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -66578,13 +66835,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -66736,10 +66994,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -67342,41 +67601,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -67440,43 +67699,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -67574,7 +67834,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -67744,16 +68005,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -67856,51 +68118,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -68276,22 +68539,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -68390,13 +68654,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -68548,10 +68813,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -69154,41 +69420,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -69252,43 +69518,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -69386,7 +69653,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -69556,16 +69824,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -69668,51 +69937,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -70088,22 +70358,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -70202,13 +70473,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -70360,10 +70632,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -70966,41 +71239,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -71064,43 +71337,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -71198,7 +71472,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -71368,16 +71643,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -71480,51 +71756,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -71900,22 +72177,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -72014,13 +72292,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -72172,10 +72451,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -72778,41 +73058,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -72876,43 +73156,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -73010,7 +73291,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -73180,16 +73462,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -73292,51 +73575,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -73712,22 +73996,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -73826,13 +74111,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -73984,10 +74270,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -74590,41 +74877,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -74688,43 +74975,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -74822,7 +75110,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -74992,16 +75281,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -75104,51 +75394,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -75524,22 +75815,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -75638,13 +75930,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -75796,10 +76089,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -76402,41 +76696,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -76500,43 +76794,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -76634,7 +76929,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -76804,16 +77100,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -76916,51 +77213,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -77336,22 +77634,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -77450,13 +77749,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -77608,10 +77908,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -78214,41 +78515,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -78312,43 +78613,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -78446,7 +78748,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -78616,16 +78919,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -78728,51 +79032,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -79148,22 +79453,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -79262,13 +79568,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -79420,10 +79727,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -80026,41 +80334,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -80124,43 +80432,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -80258,7 +80567,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -80428,16 +80738,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -80540,51 +80851,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -80960,22 +81272,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -81074,13 +81387,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -81232,10 +81546,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -81838,41 +82153,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -81936,43 +82251,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -82070,7 +82386,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -82240,16 +82557,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -82352,51 +82670,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -82772,22 +83091,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -82886,13 +83206,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -83044,10 +83365,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -83650,41 +83972,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -83748,43 +84070,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -83882,7 +84205,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -84052,16 +84376,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -84164,51 +84489,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -84584,22 +84910,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -84698,13 +85025,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -84856,10 +85184,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -85462,41 +85791,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -85560,43 +85889,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -85694,7 +86024,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -85864,16 +86195,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -85976,51 +86308,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -86396,22 +86729,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -86510,13 +86844,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -86668,10 +87003,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -87274,41 +87610,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -87372,43 +87708,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -87506,7 +87843,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -87676,16 +88014,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -87788,51 +88127,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -88208,22 +88548,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -88322,13 +88663,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -88480,10 +88822,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -89086,41 +89429,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -89184,43 +89527,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -89318,7 +89662,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -89488,16 +89833,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -89600,51 +89946,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -90020,22 +90367,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -90134,13 +90482,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -90292,10 +90641,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -90898,41 +91248,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -90996,43 +91346,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -91130,7 +91481,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -91300,16 +91652,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -91412,51 +91765,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -91832,22 +92186,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -91946,13 +92301,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -92104,10 +92460,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -92710,41 +93067,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -92808,43 +93165,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -92942,7 +93300,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -93112,16 +93471,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -93224,51 +93584,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -93644,22 +94005,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -93758,13 +94120,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -93916,10 +94279,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -94522,41 +94886,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -94620,43 +94984,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -94754,7 +95119,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -94924,16 +95290,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -95036,51 +95403,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -95456,22 +95824,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -95570,13 +95939,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -95728,10 +96098,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -96334,41 +96705,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -96432,43 +96803,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -96566,7 +96938,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -96736,16 +97109,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -96848,51 +97222,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -97268,22 +97643,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -97382,13 +97758,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -97540,10 +97917,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -98146,41 +98524,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -98244,43 +98622,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -98378,7 +98757,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -98548,16 +98928,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -98660,51 +99041,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -99080,22 +99462,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -99194,13 +99577,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -99352,10 +99736,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -99958,41 +100343,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -100056,43 +100441,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -100190,7 +100576,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -100360,16 +100747,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -100472,51 +100860,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -100892,22 +101281,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -101006,13 +101396,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -101164,10 +101555,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -101770,41 +102162,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -101868,43 +102260,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -102002,7 +102395,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -102172,16 +102566,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -102284,51 +102679,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -102704,22 +103100,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -102818,13 +103215,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -102976,10 +103374,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -103582,41 +103981,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -103680,43 +104079,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -103814,7 +104214,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -103984,16 +104385,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -104096,51 +104498,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -104516,22 +104919,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -104630,13 +105034,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -104788,10 +105193,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -105394,41 +105800,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -105492,43 +105898,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -105626,7 +106033,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -105796,16 +106204,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -105908,51 +106317,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -106328,22 +106738,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -106442,13 +106853,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -106600,10 +107012,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -107206,41 +107619,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -107304,43 +107717,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -107438,7 +107852,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -107608,16 +108023,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -107720,51 +108136,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -108140,22 +108557,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -108254,13 +108672,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -108412,10 +108831,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -109018,41 +109438,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -109116,43 +109536,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -109250,7 +109671,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -109420,16 +109842,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -109532,51 +109955,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -109952,22 +110376,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -110066,13 +110491,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -110224,10 +110650,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -110830,41 +111257,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -110928,43 +111355,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -111062,7 +111490,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -111232,16 +111661,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -111344,51 +111774,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -111764,22 +112195,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -111878,13 +112310,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -112036,10 +112469,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -112642,41 +113076,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -112740,43 +113174,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -112874,7 +113309,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -113044,16 +113480,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -113156,51 +113593,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -113576,22 +114014,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -113690,13 +114129,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -113848,10 +114288,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -114454,41 +114895,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -114552,43 +114993,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -114686,7 +115128,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -114856,16 +115299,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -114968,51 +115412,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -115388,22 +115833,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -115502,13 +115948,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -115660,10 +116107,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -116266,41 +116714,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -116364,43 +116812,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -116498,7 +116947,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -116668,16 +117118,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -116780,51 +117231,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -117200,22 +117652,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -117314,13 +117767,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -117472,10 +117926,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -118078,41 +118533,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -118176,43 +118631,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -118310,7 +118766,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -118480,16 +118937,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -118592,51 +119050,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -119012,22 +119471,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -119126,13 +119586,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -119284,10 +119745,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -119890,41 +120352,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -119988,43 +120450,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -120122,7 +120585,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -120292,16 +120756,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -120404,51 +120869,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -120824,22 +121290,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -120938,13 +121405,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -121096,10 +121564,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -121702,41 +122171,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -121800,43 +122269,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -121934,7 +122404,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -122104,16 +122575,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -122216,51 +122688,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -122636,22 +123109,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -122750,13 +123224,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -122908,10 +123383,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -123514,41 +123990,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -123612,43 +124088,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -123746,7 +124223,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -123916,16 +124394,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -124028,51 +124507,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -124448,22 +124928,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -124562,13 +125043,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -124720,10 +125202,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -125326,41 +125809,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -125424,43 +125907,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -125558,7 +126042,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -125728,16 +126213,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -125840,51 +126326,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -126260,22 +126747,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -126374,13 +126862,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -126532,10 +127021,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -127138,41 +127628,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -127236,43 +127726,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -127370,7 +127861,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -127540,16 +128032,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -127652,51 +128145,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -128072,22 +128566,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -128186,13 +128681,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -128344,10 +128840,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -128950,41 +129447,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -129048,43 +129545,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -129182,7 +129680,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -129352,16 +129851,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -129464,51 +129964,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -129884,22 +130385,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -129998,13 +130500,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -130156,10 +130659,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -130762,41 +131266,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -130860,43 +131364,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -130994,7 +131499,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -131164,16 +131670,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -131276,51 +131783,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -131696,22 +132204,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -131810,13 +132319,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -131968,10 +132478,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -132574,41 +133085,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -132672,43 +133183,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -132806,7 +133318,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -132976,16 +133489,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -133088,51 +133602,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -133508,22 +134023,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -133622,13 +134138,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -133780,10 +134297,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -134386,41 +134904,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -134484,43 +135002,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -134618,7 +135137,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -134788,16 +135308,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -134900,51 +135421,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -135320,22 +135842,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -135434,13 +135957,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -135592,10 +136116,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -136198,41 +136723,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -136296,43 +136821,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -136430,7 +136956,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -136600,16 +137127,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -136712,51 +137240,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -137132,22 +137661,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -137246,13 +137776,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -137404,10 +137935,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -138010,41 +138542,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -138108,43 +138640,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -138242,7 +138775,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -138412,16 +138946,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -138524,51 +139059,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -138944,22 +139480,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -139058,13 +139595,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -139216,10 +139754,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -139822,41 +140361,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -139920,43 +140459,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -140054,7 +140594,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -140224,16 +140765,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -140336,51 +140878,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -140756,22 +141299,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -140870,13 +141414,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -141028,10 +141573,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -141634,41 +142180,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -141732,43 +142278,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -141866,7 +142413,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -142036,16 +142584,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -142148,51 +142697,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -142568,22 +143118,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -142682,13 +143233,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -142840,10 +143392,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -143446,41 +143999,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -143544,43 +144097,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -143678,7 +144232,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -143848,16 +144403,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -143960,51 +144516,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -144380,22 +144937,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -144494,13 +145052,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -144652,10 +145211,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -145258,41 +145818,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -145356,43 +145916,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -145490,7 +146051,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -145660,16 +146222,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -145772,51 +146335,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -146192,22 +146756,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -146306,13 +146871,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -146464,10 +147030,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -147070,41 +147637,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -147168,43 +147735,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -147302,7 +147870,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -147472,16 +148041,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -147584,51 +148154,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -148004,22 +148575,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -148118,13 +148690,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -148276,10 +148849,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -148882,41 +149456,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -148980,43 +149554,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -149114,7 +149689,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -149284,16 +149860,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -149396,51 +149973,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -149816,22 +150394,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -149930,13 +150509,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -150088,10 +150668,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -150694,41 +151275,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -150792,43 +151373,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -150926,7 +151508,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -151096,16 +151679,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -151208,51 +151792,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -151628,22 +152213,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -151742,13 +152328,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -151900,10 +152487,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -152506,41 +153094,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -152604,43 +153192,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -152738,7 +153327,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -152908,16 +153498,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -153020,51 +153611,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -153440,22 +154032,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -153554,13 +154147,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -153712,10 +154306,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -154318,41 +154913,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -154416,43 +155011,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -154550,7 +155146,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -154720,16 +155317,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -154832,51 +155430,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -155252,22 +155851,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -155366,13 +155966,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -155524,10 +156125,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -156130,41 +156732,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -156228,43 +156830,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -156362,7 +156965,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -156532,16 +157136,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -156644,51 +157249,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -157064,22 +157670,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -157178,13 +157785,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -157336,10 +157944,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -157942,41 +158551,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -158040,43 +158649,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -158174,7 +158784,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -158344,16 +158955,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -158456,51 +159068,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -158876,22 +159489,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -158990,13 +159604,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -159148,10 +159763,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -159754,41 +160370,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -159852,43 +160468,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -159986,7 +160603,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -160156,16 +160774,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -160268,51 +160887,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -160688,22 +161308,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -160802,13 +161423,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -160960,10 +161582,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -161566,41 +162189,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -161664,43 +162287,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -161798,7 +162422,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -161968,16 +162593,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -162080,51 +162706,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -162500,22 +163127,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -162614,13 +163242,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -162772,10 +163401,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -163378,41 +164008,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -163476,43 +164106,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -163610,7 +164241,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -163780,16 +164412,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -163892,51 +164525,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -164312,22 +164946,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -164426,13 +165061,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -164584,10 +165220,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -165190,41 +165827,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -165288,43 +165925,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -165422,7 +166060,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -165592,16 +166231,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -165704,51 +166344,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -166124,22 +166765,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -166238,13 +166880,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -166396,10 +167039,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -167002,41 +167646,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -167100,43 +167744,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -167234,7 +167879,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -167404,16 +168050,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -167516,51 +168163,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -167936,22 +168584,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -168050,13 +168699,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -168208,10 +168858,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -168814,41 +169465,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -168912,43 +169563,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -169046,7 +169698,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -169216,16 +169869,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -169328,51 +169982,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -169748,22 +170403,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -169862,13 +170518,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -170020,10 +170677,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -170626,41 +171284,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -170724,43 +171382,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -170858,7 +171517,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -171028,16 +171688,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -171140,51 +171801,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -171560,22 +172222,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -171674,13 +172337,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -171832,10 +172496,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -172438,41 +173103,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -172536,43 +173201,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -172670,7 +173336,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -172840,16 +173507,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -172952,51 +173620,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -173372,22 +174041,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -173486,13 +174156,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -173644,10 +174315,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -174250,41 +174922,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -174348,43 +175020,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -174482,7 +175155,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -174652,16 +175326,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -174764,51 +175439,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -175184,22 +175860,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -175298,13 +175975,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -175456,10 +176134,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -176062,41 +176741,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -176160,43 +176839,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -176294,7 +176974,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -176464,16 +177145,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -176576,51 +177258,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -176996,22 +177679,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -177110,13 +177794,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -177268,10 +177953,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -177874,41 +178560,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -177972,43 +178658,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -178106,7 +178793,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -178276,16 +178964,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -178388,51 +179077,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -178808,22 +179498,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -178922,13 +179613,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -179080,10 +179772,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -179686,41 +180379,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -179784,43 +180477,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -179918,7 +180612,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -180088,16 +180783,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -180200,51 +180896,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -180620,22 +181317,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -180734,13 +181432,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -180892,10 +181591,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -181498,41 +182198,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -181596,43 +182296,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -181730,7 +182431,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -181900,16 +182602,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -182012,51 +182715,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -182432,22 +183136,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -182546,13 +183251,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -182704,10 +183410,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -183310,41 +184017,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -183408,43 +184115,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -183542,7 +184250,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -183712,16 +184421,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -183824,51 +184534,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -184244,22 +184955,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -184358,13 +185070,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -184516,10 +185229,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -185122,41 +185836,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -185220,43 +185934,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -185354,7 +186069,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -185524,16 +186240,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -185636,51 +186353,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -186056,22 +186774,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -186170,13 +186889,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -186328,10 +187048,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -186934,41 +187655,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -187032,43 +187753,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -187166,7 +187888,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -187336,16 +188059,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -187448,51 +188172,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -187868,22 +188593,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -187982,13 +188708,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -188140,10 +188867,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -188746,41 +189474,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -188844,43 +189572,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -188978,7 +189707,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -189148,16 +189878,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -189260,51 +189991,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -189680,22 +190412,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -189794,13 +190527,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -189952,10 +190686,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -190558,41 +191293,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -190656,43 +191391,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -190790,7 +191526,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -190960,16 +191697,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -191072,51 +191810,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -191492,22 +192231,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -191606,13 +192346,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -191764,10 +192505,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -192370,41 +193112,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -192468,43 +193210,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -192602,7 +193345,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -192772,16 +193516,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -192884,51 +193629,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -193304,22 +194050,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -193418,13 +194165,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -193576,10 +194324,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -194182,41 +194931,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -194280,43 +195029,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -194414,7 +195164,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -194584,16 +195335,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -194696,51 +195448,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -195116,22 +195869,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -195230,13 +195984,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -195388,10 +196143,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -195994,41 +196750,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -196092,43 +196848,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -196226,7 +196983,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -196396,16 +197154,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -196508,51 +197267,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -196928,22 +197688,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -197042,13 +197803,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -197200,10 +197962,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -197806,41 +198569,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -197904,43 +198667,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -198038,7 +198802,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -198208,16 +198973,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -198320,51 +199086,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -198740,22 +199507,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -198854,13 +199622,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -199012,10 +199781,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -199618,41 +200388,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -199716,43 +200486,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -199850,7 +200621,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -200020,16 +200792,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -200132,51 +200905,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -200552,22 +201326,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -200666,13 +201441,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -200824,10 +201600,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -201430,41 +202207,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -201528,43 +202305,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -201662,7 +202440,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -201832,16 +202611,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -201944,51 +202724,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -202364,22 +203145,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -202478,13 +203260,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -202636,10 +203419,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -203242,41 +204026,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -203340,43 +204124,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -203474,7 +204259,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -203644,16 +204430,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -203756,51 +204543,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -204176,22 +204964,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -204290,13 +205079,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -204448,10 +205238,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -205054,41 +205845,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -205152,43 +205943,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -205286,7 +206078,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -205456,16 +206249,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -205568,51 +206362,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -205988,22 +206783,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -206102,13 +206898,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -206260,10 +207057,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -206866,41 +207664,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -206964,43 +207762,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -207098,7 +207897,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -207268,16 +208068,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -207380,51 +208181,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -207800,22 +208602,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -207914,13 +208717,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -208072,10 +208876,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -208678,41 +209483,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -208776,43 +209581,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -208910,7 +209716,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -209080,16 +209887,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -209192,51 +210000,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -209612,22 +210421,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -209726,13 +210536,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -209884,10 +210695,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -210490,41 +211302,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -210588,43 +211400,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -210722,7 +211535,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -210892,16 +211706,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -211004,51 +211819,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -211424,22 +212240,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -211538,13 +212355,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -211696,10 +212514,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -212302,41 +213121,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -212400,43 +213219,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -212534,7 +213354,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -212704,16 +213525,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -212816,51 +213638,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -213236,22 +214059,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -213350,13 +214174,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -213508,10 +214333,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -214114,41 +214940,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -214212,43 +215038,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -214346,7 +215173,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -214516,16 +215344,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -214628,51 +215457,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -215048,22 +215878,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -215162,13 +215993,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -215320,10 +216152,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -215926,41 +216759,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -216024,43 +216857,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -216158,7 +216992,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -216328,16 +217163,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -216440,51 +217276,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -216860,22 +217697,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -216974,13 +217812,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -217132,10 +217971,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -217738,41 +218578,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -217836,43 +218676,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -217970,7 +218811,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -218140,16 +218982,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -218252,51 +219095,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -218672,22 +219516,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -218786,13 +219631,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -218944,10 +219790,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -219550,41 +220397,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -219648,43 +220495,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -219782,7 +220630,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -219952,16 +220801,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -220064,51 +220914,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -220484,22 +221335,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -220598,13 +221450,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -220756,10 +221609,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -221362,41 +222216,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -221460,43 +222314,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -221594,7 +222449,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -221764,16 +222620,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -221876,51 +222733,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -222296,22 +223154,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -222410,13 +223269,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -222568,10 +223428,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -223174,41 +224035,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -223272,43 +224133,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -223406,7 +224268,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -223576,16 +224439,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -223688,51 +224552,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -224108,22 +224973,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -224222,13 +225088,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -224380,10 +225247,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -224986,41 +225854,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -225084,43 +225952,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -225218,7 +226087,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -225388,16 +226258,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -225500,51 +226371,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -225920,22 +226792,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -226034,13 +226907,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -226192,10 +227066,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -226798,41 +227673,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -226896,43 +227771,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -227030,7 +227906,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -227200,16 +228077,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -227312,51 +228190,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -227732,22 +228611,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -227846,13 +228726,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -228004,10 +228885,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -228610,41 +229492,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -228708,43 +229590,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -228842,7 +229725,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -229012,16 +229896,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -229124,51 +230009,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -229544,22 +230430,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -229658,13 +230545,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -229816,10 +230704,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -230422,41 +231311,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -230520,43 +231409,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -230654,7 +231544,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -230824,16 +231715,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -230936,51 +231828,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -231356,22 +232249,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -231470,13 +232364,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -231628,10 +232523,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -232234,41 +233130,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -232332,43 +233228,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -232466,7 +233363,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -232636,16 +233534,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -232748,51 +233647,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -233168,22 +234068,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -233282,13 +234183,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -233440,10 +234342,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -234046,41 +234949,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -234144,43 +235047,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -234278,7 +235182,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -234448,16 +235353,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -234560,51 +235466,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -234980,22 +235887,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -235094,13 +236002,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -235252,10 +236161,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -235858,41 +236768,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -235956,43 +236866,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -236090,7 +237001,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -236260,16 +237172,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -236372,51 +237285,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -236792,22 +237706,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -236906,13 +237821,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -237064,10 +237980,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -237670,41 +238587,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -237768,43 +238685,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -237902,7 +238820,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -238072,16 +238991,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -238184,51 +239104,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -238604,22 +239525,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -238718,13 +239640,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -238876,10 +239799,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -239482,41 +240406,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -239580,43 +240504,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -239714,7 +240639,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -239884,16 +240810,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -239996,51 +240923,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -240416,22 +241344,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -240530,13 +241459,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -240688,10 +241618,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -241294,41 +242225,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -241392,43 +242323,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -241526,7 +242458,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -241696,16 +242629,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -241808,51 +242742,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -242228,22 +243163,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -242342,13 +243278,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -242500,10 +243437,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -243106,41 +244044,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -243204,43 +244142,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -243338,7 +244277,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -243508,16 +244448,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -243620,51 +244561,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -244040,22 +244982,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -244154,13 +245097,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -244312,10 +245256,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -244918,41 +245863,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -245016,43 +245961,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -245150,7 +246096,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -245320,16 +246267,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -245432,51 +246380,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -245852,22 +246801,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -245966,13 +246916,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -246124,10 +247075,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -246730,41 +247682,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -246828,43 +247780,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -246962,7 +247915,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -247132,16 +248086,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -247244,51 +248199,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -247664,22 +248620,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -247778,13 +248735,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -247936,10 +248894,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -248542,41 +249501,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -248640,43 +249599,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -248774,7 +249734,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -248944,16 +249905,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -249056,51 +250018,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -249476,22 +250439,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -249590,13 +250554,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -249748,10 +250713,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -250354,41 +251320,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -250452,43 +251418,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -250586,7 +251553,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -250756,16 +251724,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -250868,51 +251837,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -251288,22 +252258,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -251402,13 +252373,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -251560,10 +252532,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -252166,41 +253139,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -252264,43 +253237,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -252398,7 +253372,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -252568,16 +253543,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -252680,51 +253656,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -253100,22 +254077,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -253214,13 +254192,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -253372,10 +254351,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -253978,41 +254958,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -254076,43 +255056,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -254210,7 +255191,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -254380,16 +255362,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -254492,51 +255475,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -254912,22 +255896,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -255026,13 +256011,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -255184,10 +256170,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -255790,41 +256777,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -255888,43 +256875,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -256022,7 +257010,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -256192,16 +257181,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -256304,51 +257294,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -256724,22 +257715,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -256838,13 +257830,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -256996,10 +257989,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -257602,41 +258596,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -257700,43 +258694,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -257834,7 +258829,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -258004,16 +259000,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -258116,51 +259113,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -258536,22 +259534,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -258650,13 +259649,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -258808,10 +259808,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -259414,41 +260415,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -259512,43 +260513,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -259646,7 +260648,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -259816,16 +260819,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -259928,51 +260932,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -260348,22 +261353,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -260462,13 +261468,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -260620,10 +261627,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -261226,41 +262234,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -261324,43 +262332,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -261458,7 +262467,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -261628,16 +262638,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -261740,51 +262751,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -262160,22 +263172,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -262274,13 +263287,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -262432,10 +263446,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -263038,41 +264053,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -263136,43 +264151,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -263270,7 +264286,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -263440,16 +264457,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -263552,51 +264570,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -263972,22 +264991,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -264086,13 +265106,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -264244,10 +265265,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -264850,41 +265872,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -264948,43 +265970,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -265082,7 +266105,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -265252,16 +266276,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -265364,51 +266389,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -265784,22 +266810,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -265898,13 +266925,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -266056,10 +267084,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -266662,41 +267691,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -266760,43 +267789,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -266894,7 +267924,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -267064,16 +268095,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -267176,51 +268208,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -267596,22 +268629,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -267710,13 +268744,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -267868,10 +268903,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -268474,41 +269510,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -268572,43 +269608,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -268706,7 +269743,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -268876,16 +269914,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -268988,51 +270027,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -269408,22 +270448,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -269522,13 +270563,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -269680,10 +270722,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -270286,41 +271329,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -270384,43 +271427,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -270518,7 +271562,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -270688,16 +271733,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -270800,51 +271846,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -271220,22 +272267,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -271334,13 +272382,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -271492,10 +272541,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -272098,41 +273148,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -272196,43 +273246,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -272330,7 +273381,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -272500,16 +273552,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -272612,51 +273665,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -273032,22 +274086,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -273146,13 +274201,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -273304,10 +274360,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -273910,41 +274967,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -274008,43 +275065,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -274142,7 +275200,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -274312,16 +275371,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -274424,51 +275484,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -274844,22 +275905,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -274958,13 +276020,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -275116,10 +276179,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -275722,41 +276786,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -275820,43 +276884,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -275954,7 +277019,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -276124,16 +277190,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -276236,51 +277303,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -276656,22 +277724,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -276770,13 +277839,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -276928,10 +277998,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -277534,41 +278605,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -277632,43 +278703,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -277766,7 +278838,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -277936,16 +279009,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -278048,51 +279122,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -278468,22 +279543,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -278582,13 +279658,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -278740,10 +279817,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -279346,41 +280424,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -279444,43 +280522,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -279578,7 +280657,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -279748,16 +280828,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -279860,51 +280941,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -280280,22 +281362,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -280394,13 +281477,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -280552,10 +281636,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -281158,41 +282243,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -281256,43 +282341,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -281390,7 +282476,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -281560,16 +282647,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -281672,51 +282760,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -282092,22 +283181,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -282206,13 +283296,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -282364,10 +283455,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -282970,41 +284062,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -283068,43 +284160,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -283202,7 +284295,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -283372,16 +284466,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -283484,51 +284579,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -283904,22 +285000,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -284018,13 +285115,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -284176,10 +285274,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -284782,41 +285881,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -284880,43 +285979,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -285014,7 +286114,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -285184,16 +286285,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -285296,51 +286398,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -285716,22 +286819,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -285830,13 +286934,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -285988,10 +287093,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -286594,41 +287700,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -286692,43 +287798,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -286826,7 +287933,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -286996,16 +288104,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -287108,51 +288217,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -287528,22 +288638,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -287642,13 +288753,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -287800,10 +288912,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -288406,41 +289519,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -288504,43 +289617,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -288638,7 +289752,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -288808,16 +289923,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -288920,51 +290036,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -289340,22 +290457,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -289454,13 +290572,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -289612,10 +290731,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -290218,41 +291338,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -290316,43 +291436,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -290450,7 +291571,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -290620,16 +291742,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -290732,51 +291855,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -291152,22 +292276,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -291266,13 +292391,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -291424,10 +292550,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -292030,41 +293157,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -292128,43 +293255,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -292262,7 +293390,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -292432,16 +293561,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -292544,51 +293674,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -292964,22 +294095,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -293078,13 +294210,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -293236,10 +294369,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -293842,41 +294976,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -293940,43 +295074,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -294074,7 +295209,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -294244,16 +295380,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -294356,51 +295493,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -294776,22 +295914,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -294890,13 +296029,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -295048,10 +296188,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -295654,41 +296795,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -295752,43 +296893,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -295886,7 +297028,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -296056,16 +297199,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -296168,51 +297312,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -296588,22 +297733,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -296702,13 +297848,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -296860,10 +298007,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -297466,41 +298614,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -297564,43 +298712,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -297698,7 +298847,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -297868,16 +299018,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -297980,51 +299131,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -298400,22 +299552,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -298514,13 +299667,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -298672,10 +299826,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -299278,41 +300433,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -299376,43 +300531,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -299510,7 +300666,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -299680,16 +300837,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -299792,51 +300950,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -300212,22 +301371,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -300326,13 +301486,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -300484,10 +301645,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -301090,41 +302252,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -301188,43 +302350,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -301322,7 +302485,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -301492,16 +302656,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -301604,51 +302769,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -302024,22 +303190,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -302138,13 +303305,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -302296,10 +303464,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -302902,41 +304071,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -303000,43 +304169,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -303134,7 +304304,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -303304,16 +304475,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -303416,51 +304588,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -303836,22 +305009,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -303950,13 +305124,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -304108,10 +305283,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -304714,41 +305890,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -304812,43 +305988,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -304946,7 +306123,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -305116,16 +306294,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -305228,51 +306407,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -305648,22 +306828,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -305762,13 +306943,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -305920,10 +307102,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -306526,41 +307709,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -306624,43 +307807,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -306758,7 +307942,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -306928,16 +308113,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -307040,51 +308226,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -307460,22 +308647,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -307574,13 +308762,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -307732,10 +308921,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -308338,41 +309528,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -308436,43 +309626,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -308570,7 +309761,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -308740,16 +309932,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -308852,51 +310045,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -309272,22 +310466,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -309386,13 +310581,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -309544,10 +310740,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -310150,41 +311347,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -310248,43 +311445,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -310382,7 +311580,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -310552,16 +311751,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -310664,51 +311864,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -311084,22 +312285,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -311198,13 +312400,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -311356,10 +312559,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -311962,41 +313166,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -312060,43 +313264,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -312194,7 +313399,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -312364,16 +313570,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -312476,51 +313683,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -312896,22 +314104,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -313010,13 +314219,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -313168,10 +314378,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -313774,41 +314985,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -313872,43 +315083,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -314006,7 +315218,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -314176,16 +315389,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -314288,51 +315502,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -314708,22 +315923,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -314822,13 +316038,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -314980,10 +316197,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -315586,41 +316804,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -315684,43 +316902,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -315818,7 +317037,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -315988,16 +317208,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -316100,51 +317321,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -316520,22 +317742,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -316634,13 +317857,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -316792,10 +318016,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -317398,41 +318623,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -317496,43 +318721,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -317630,7 +318856,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -317800,16 +319027,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -317912,51 +319140,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -318332,22 +319561,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -318446,13 +319676,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -318604,10 +319835,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -319210,41 +320442,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -319308,43 +320540,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -319442,7 +320675,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -319612,16 +320846,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -319724,51 +320959,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -320144,22 +321380,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -320258,13 +321495,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -320416,10 +321654,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -321022,41 +322261,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -321120,43 +322359,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -321254,7 +322494,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -321424,16 +322665,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -321536,51 +322778,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -321956,22 +323199,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -322070,13 +323314,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -322228,10 +323473,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -322834,41 +324080,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -322932,43 +324178,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -323066,7 +324313,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -323236,16 +324484,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -323348,51 +324597,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -323768,22 +325018,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -323882,13 +325133,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -324040,10 +325292,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -324646,41 +325899,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -324744,43 +325997,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -324878,7 +326132,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -325048,16 +326303,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -325160,51 +326416,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -325580,22 +326837,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -325694,13 +326952,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -325852,10 +327111,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -326458,41 +327718,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -326556,43 +327816,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -326690,7 +327951,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -326860,16 +328122,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -326972,51 +328235,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -327392,22 +328656,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -327506,13 +328771,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -327664,10 +328930,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -328270,41 +329537,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -328368,43 +329635,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -328502,7 +329770,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -328672,16 +329941,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -328784,51 +330054,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -329204,22 +330475,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -329318,13 +330590,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -329476,10 +330749,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -330082,41 +331356,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -330180,43 +331454,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -330314,7 +331589,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -330484,16 +331760,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -330596,51 +331873,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -331016,22 +332294,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -331130,13 +332409,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -331288,10 +332568,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -331894,41 +333175,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -331992,43 +333273,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -332126,7 +333408,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -332296,16 +333579,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -332408,51 +333692,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -332828,22 +334113,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -332942,13 +334228,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -333100,10 +334387,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -333706,41 +334994,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -333804,43 +335092,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -333938,7 +335227,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -334108,16 +335398,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -334220,51 +335511,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -334640,22 +335932,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -334754,13 +336047,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -334912,10 +336206,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -335518,41 +336813,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -335616,43 +336911,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -335750,7 +337046,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -335920,16 +337217,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -336032,51 +337330,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -336452,22 +337751,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -336566,13 +337866,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -336724,10 +338025,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -337330,41 +338632,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -337428,43 +338730,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -337562,7 +338865,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -337732,16 +339036,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -337844,51 +339149,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -338264,22 +339570,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -338378,13 +339685,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -338536,10 +339844,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -339142,41 +340451,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -339240,43 +340549,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -339374,7 +340684,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -339544,16 +340855,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -339656,51 +340968,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -340076,22 +341389,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -340190,13 +341504,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -340348,10 +341663,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -340954,41 +342270,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -341052,43 +342368,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -341186,7 +342503,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -341356,16 +342674,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -341468,51 +342787,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -341888,22 +343208,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -342002,13 +343323,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -342160,10 +343482,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -342766,41 +344089,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -342864,43 +344187,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -342998,7 +344322,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -343168,16 +344493,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -343280,51 +344606,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -343700,22 +345027,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -343814,13 +345142,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -343972,10 +345301,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -344578,41 +345908,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -344676,43 +346006,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -344810,7 +346141,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -344980,16 +346312,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -345092,51 +346425,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -345512,22 +346846,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -345626,13 +346961,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -345784,10 +347120,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -346390,41 +347727,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -346488,43 +347825,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -346622,7 +347960,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -346792,16 +348131,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -346904,51 +348244,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -347324,22 +348665,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -347438,13 +348780,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -347596,10 +348939,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -348202,41 +349546,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -348300,43 +349644,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -348434,7 +349779,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -348604,16 +349950,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -348716,51 +350063,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -349136,22 +350484,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -349250,13 +350599,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -349408,10 +350758,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -350014,41 +351365,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -350112,43 +351463,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -350246,7 +351598,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -350416,16 +351769,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -350528,51 +351882,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -350948,22 +352303,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -351062,13 +352418,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -351220,10 +352577,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -351826,41 +353184,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -351924,43 +353282,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -352058,7 +353417,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -352228,16 +353588,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -352340,51 +353701,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -352760,22 +354122,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -352874,13 +354237,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -353032,10 +354396,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -353638,41 +355003,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -353736,43 +355101,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -353870,7 +355236,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -354040,16 +355407,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -354152,51 +355520,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -354572,22 +355941,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -354686,13 +356056,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -354844,10 +356215,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -355450,41 +356822,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -355548,43 +356920,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -355682,7 +357055,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -355852,16 +357226,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -355964,51 +357339,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -356384,22 +357760,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -356498,13 +357875,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -356656,10 +358034,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -357262,41 +358641,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -357360,43 +358739,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -357494,7 +358874,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -357664,16 +359045,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -357776,51 +359158,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -358196,22 +359579,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -358310,13 +359694,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -358468,10 +359853,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -359074,41 +360460,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -359172,43 +360558,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -359306,7 +360693,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -359476,16 +360864,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -359588,51 +360977,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -360008,22 +361398,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -360122,13 +361513,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -360280,10 +361672,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -360886,41 +362279,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -360984,43 +362377,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -361118,7 +362512,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -361288,16 +362683,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -361400,51 +362796,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -361820,22 +363217,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -361934,13 +363332,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -362092,10 +363491,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -362698,41 +364098,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -362796,43 +364196,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -362930,7 +364331,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -363100,16 +364502,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -363212,51 +364615,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -363632,22 +365036,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -363746,13 +365151,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -363904,10 +365310,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -364510,41 +365917,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -364608,43 +366015,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -364742,7 +366150,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -364912,16 +366321,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -365024,51 +366434,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -365444,22 +366855,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -365558,13 +366970,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -365716,10 +367129,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -366322,41 +367736,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -366420,43 +367834,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -366554,7 +367969,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -366724,16 +368140,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -366836,51 +368253,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -367256,22 +368674,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -367370,13 +368789,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -367528,10 +368948,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -368134,41 +369555,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -368232,43 +369653,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -368366,7 +369788,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -368536,16 +369959,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -368648,51 +370072,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -369068,22 +370493,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -369182,13 +370608,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -369340,10 +370767,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -369946,41 +371374,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -370044,43 +371472,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -370178,7 +371607,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -370348,16 +371778,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -370460,51 +371891,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -370880,22 +372312,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -370994,13 +372427,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -371152,10 +372586,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -371758,41 +373193,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -371856,43 +373291,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -371990,7 +373426,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -372160,16 +373597,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -372272,51 +373710,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -372692,22 +374131,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -372806,13 +374246,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -372964,10 +374405,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -373570,41 +375012,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -373668,43 +375110,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -373802,7 +375245,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -373972,16 +375416,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -374084,51 +375529,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -374504,22 +375950,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -374618,13 +376065,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -374776,10 +376224,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -375382,41 +376831,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -375480,43 +376929,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -375614,7 +377064,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -375784,16 +377235,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -375896,51 +377348,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -376316,22 +377769,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -376430,13 +377884,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -376588,10 +378043,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -377194,41 +378650,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -377292,43 +378748,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -377426,7 +378883,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -377596,16 +379054,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -377708,51 +379167,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -378128,22 +379588,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -378242,13 +379703,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -378400,10 +379862,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -379006,41 +380469,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -379104,43 +380567,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -379238,7 +380702,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -379408,16 +380873,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -379520,51 +380986,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -379940,22 +381407,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -380054,13 +381522,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -380212,10 +381681,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -380818,41 +382288,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -380916,43 +382386,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -381050,7 +382521,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -381220,16 +382692,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -381332,51 +382805,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -381752,22 +383226,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -381866,13 +383341,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -382024,10 +383500,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -382630,41 +384107,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -382728,43 +384205,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -382862,7 +384340,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -383032,16 +384511,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -383144,51 +384624,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -383564,22 +385045,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -383678,13 +385160,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -383836,10 +385319,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -384442,41 +385926,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -384540,43 +386024,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -384674,7 +386159,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -384844,16 +386330,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -384956,51 +386443,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -385376,22 +386864,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -385490,13 +386979,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -385648,10 +387138,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -386254,41 +387745,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -386352,43 +387843,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -386486,7 +387978,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -386656,16 +388149,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -386768,51 +388262,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -387188,22 +388683,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -387302,13 +388798,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -387460,10 +388957,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -388066,41 +389564,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -388164,43 +389662,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -388298,7 +389797,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -388468,16 +389968,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -388580,51 +390081,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -389000,22 +390502,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -389114,13 +390617,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -389272,10 +390776,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -389878,41 +391383,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -389976,43 +391481,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -390110,7 +391616,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -390280,16 +391787,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -390392,51 +391900,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -390812,22 +392321,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -390926,13 +392436,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -391084,10 +392595,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -391690,41 +393202,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -391788,43 +393300,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -391922,7 +393435,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -392092,16 +393606,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -392204,51 +393719,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -392624,22 +394140,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -392738,13 +394255,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -392896,10 +394414,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -393502,41 +395021,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -393600,43 +395119,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -393734,7 +395254,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -393904,16 +395425,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -394016,51 +395538,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -394436,22 +395959,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -394550,13 +396074,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -394708,10 +396233,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -395314,41 +396840,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -395412,43 +396938,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -395546,7 +397073,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -395716,16 +397244,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -395828,51 +397357,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -396248,22 +397778,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -396362,13 +397893,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -396520,10 +398052,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -397126,41 +398659,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -397224,43 +398757,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -397358,7 +398892,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -397528,16 +399063,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -397640,51 +399176,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -398060,22 +399597,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -398174,13 +399712,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -398332,10 +399871,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -398938,41 +400478,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -399036,43 +400576,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -399170,7 +400711,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -399340,16 +400882,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -399452,51 +400995,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -399872,22 +401416,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -399986,13 +401531,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -400144,10 +401690,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -400750,41 +402297,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -400848,43 +402395,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -400982,7 +402530,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -401152,16 +402701,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -401264,51 +402814,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -401684,22 +403235,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -401798,13 +403350,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -401956,10 +403509,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -402562,41 +404116,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -402660,43 +404214,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -402794,7 +404349,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -402964,16 +404520,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -403076,51 +404633,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -403496,22 +405054,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -403610,13 +405169,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -403768,10 +405328,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -404374,41 +405935,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -404472,43 +406033,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -404606,7 +406168,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -404776,16 +406339,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -404888,51 +406452,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -405308,22 +406873,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -405422,13 +406988,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -405580,10 +407147,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -406186,41 +407754,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -406284,43 +407852,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -406418,7 +407987,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -406588,16 +408158,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -406700,51 +408271,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -407120,22 +408692,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -407234,13 +408807,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -407392,10 +408966,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -407998,41 +409573,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -408096,43 +409671,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -408230,7 +409806,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -408400,16 +409977,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -408512,51 +410090,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -408932,22 +410511,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -409046,13 +410626,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -409204,10 +410785,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -409810,41 +411392,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -409908,43 +411490,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -410042,7 +411625,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -410212,16 +411796,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -410324,51 +411909,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -410744,22 +412330,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -410858,13 +412445,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -411016,10 +412604,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -411622,41 +413211,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -411720,43 +413309,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -411854,7 +413444,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -412024,16 +413615,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -412136,51 +413728,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -412556,22 +414149,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -412670,13 +414264,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -412828,10 +414423,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -413434,41 +415030,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -413532,43 +415128,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -413666,7 +415263,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -413836,16 +415434,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -413948,51 +415547,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -414368,22 +415968,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -414482,13 +416083,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -414640,10 +416242,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -415246,41 +416849,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -415344,43 +416947,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -415478,7 +417082,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -415648,16 +417253,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -415760,51 +417366,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -416180,22 +417787,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -416294,13 +417902,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -416452,10 +418061,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -417058,41 +418668,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -417156,43 +418766,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -417290,7 +418901,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -417460,16 +419072,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -417572,51 +419185,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -417992,22 +419606,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -418106,13 +419721,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -418264,10 +419880,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -418870,41 +420487,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -418968,43 +420585,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -419102,7 +420720,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -419272,16 +420891,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -419384,51 +421004,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -419804,22 +421425,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -419918,13 +421540,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -420076,10 +421699,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -420682,41 +422306,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -420780,43 +422404,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -420914,7 +422539,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -421084,16 +422710,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -421196,51 +422823,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -421616,22 +423244,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -421730,13 +423359,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -421888,10 +423518,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -422494,41 +424125,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -422592,43 +424223,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -422726,7 +424358,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -422896,16 +424529,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -423008,51 +424642,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -423428,22 +425063,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -423542,13 +425178,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -423700,10 +425337,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -424306,41 +425944,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -424404,43 +426042,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -424538,7 +426177,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -424708,16 +426348,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -424820,51 +426461,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -425240,22 +426882,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -425354,13 +426997,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -425512,10 +427156,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -426118,41 +427763,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -426216,43 +427861,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -426350,7 +427996,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -426520,16 +428167,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -426632,51 +428280,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -427052,22 +428701,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -427166,13 +428816,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -427324,10 +428975,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -427930,41 +429582,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -428028,43 +429680,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -428162,7 +429815,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -428332,16 +429986,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -428444,51 +430099,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -428864,22 +430520,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -428978,13 +430635,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -429136,10 +430794,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -429742,41 +431401,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -429840,43 +431499,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -429974,7 +431634,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -430144,16 +431805,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -430256,51 +431918,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -430676,22 +432339,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -430790,13 +432454,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -430948,10 +432613,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -431554,41 +433220,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -431652,43 +433318,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -431786,7 +433453,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -431956,16 +433624,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -432068,51 +433737,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -432488,22 +434158,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -432602,13 +434273,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -432760,10 +434432,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -433366,41 +435039,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -433464,43 +435137,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -433598,7 +435272,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -433768,16 +435443,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -433880,51 +435556,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -434300,22 +435977,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -434414,13 +436092,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -434572,10 +436251,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -435178,41 +436858,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -435276,43 +436956,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -435410,7 +437091,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -435580,16 +437262,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -435692,51 +437375,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -436112,22 +437796,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -436226,13 +437911,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -436384,10 +438070,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -436990,41 +438677,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -437088,43 +438775,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -437222,7 +438910,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -437392,16 +439081,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -437504,51 +439194,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -437924,22 +439615,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -438038,13 +439730,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -438196,10 +439889,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -438802,41 +440496,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -438900,43 +440594,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -439034,7 +440729,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -439204,16 +440900,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -439316,51 +441013,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -439736,22 +441434,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -439850,13 +441549,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -440008,10 +441708,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -440614,41 +442315,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -440712,43 +442413,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -440846,7 +442548,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -441016,16 +442719,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -441128,51 +442832,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -441548,22 +443253,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -441662,13 +443368,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -441820,10 +443527,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -442426,41 +444134,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -442524,43 +444232,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -442658,7 +444367,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -442828,16 +444538,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -442940,51 +444651,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -443360,22 +445072,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -443474,13 +445187,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -443632,10 +445346,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -444238,41 +445953,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -444336,43 +446051,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -444470,7 +446186,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -444640,16 +446357,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -444752,51 +446470,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -445172,22 +446891,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -445286,13 +447006,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -445444,10 +447165,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -446050,41 +447772,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -446148,43 +447870,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -446282,7 +448005,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -446452,16 +448176,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -446564,51 +448289,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -446984,22 +448710,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -447098,13 +448825,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -447256,10 +448984,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -447862,41 +449591,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -447960,43 +449689,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -448094,7 +449824,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -448264,16 +449995,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -448376,51 +450108,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -448796,22 +450529,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -448910,13 +450644,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -449068,10 +450803,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -449674,41 +451410,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -449772,43 +451508,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -449906,7 +451643,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -450076,16 +451814,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -450188,51 +451927,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -450608,22 +452348,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -450722,13 +452463,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -450880,10 +452622,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -451486,41 +453229,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -451584,43 +453327,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -451718,7 +453462,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -451888,16 +453633,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -452000,51 +453746,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -452420,22 +454167,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -452534,13 +454282,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -452692,10 +454441,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -453298,41 +455048,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -453396,43 +455146,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -453530,7 +455281,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -453700,16 +455452,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -453812,51 +455565,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -454232,22 +455986,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -454346,13 +456101,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -454504,10 +456260,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -455110,41 +456867,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -455208,43 +456965,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -455342,7 +457100,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -455512,16 +457271,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -455624,51 +457384,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -456044,22 +457805,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -456158,13 +457920,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -456316,10 +458079,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -456922,41 +458686,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -457020,43 +458784,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -457154,7 +458919,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -457324,16 +459090,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -457436,51 +459203,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -457856,22 +459624,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -457970,13 +459739,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -458128,10 +459898,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -458734,41 +460505,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -458832,43 +460603,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -458966,7 +460738,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -459136,16 +460909,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -459248,51 +461022,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -459668,22 +461443,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -459782,13 +461558,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -459940,10 +461717,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -460546,41 +462324,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -460644,43 +462422,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -460778,7 +462557,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -460948,16 +462728,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -461060,51 +462841,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -461480,22 +463262,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -461594,13 +463377,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -461752,10 +463536,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -462358,41 +464143,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -462456,43 +464241,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -462590,7 +464376,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -462760,16 +464547,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -462872,51 +464660,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -463292,22 +465081,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -463406,13 +465196,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -463564,10 +465355,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -464170,41 +465962,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -464268,43 +466060,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -464402,7 +466195,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -464572,16 +466366,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -464684,51 +466479,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -465104,22 +466900,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -465218,13 +467015,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -465376,10 +467174,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -465982,41 +467781,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -466080,43 +467879,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -466214,7 +468014,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -466384,16 +468185,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -466496,51 +468298,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -466916,22 +468719,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -467030,13 +468834,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -467188,10 +468993,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -467794,41 +469600,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -467892,43 +469698,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -468026,7 +469833,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -468196,16 +470004,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -468308,51 +470117,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -468728,22 +470538,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -468842,13 +470653,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -469000,10 +470812,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -469606,41 +471419,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -469704,43 +471517,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -469838,7 +471652,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -470008,16 +471823,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -470120,51 +471936,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -470540,22 +472357,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -470654,13 +472472,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -470812,10 +472631,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -471418,41 +473238,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -471516,43 +473336,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -471650,7 +473471,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -471820,16 +473642,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -471932,51 +473755,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -472352,22 +474176,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -472466,13 +474291,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -472624,10 +474450,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -473230,41 +475057,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -473328,43 +475155,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -473462,7 +475290,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -473632,16 +475461,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -473744,51 +475574,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -474164,22 +475995,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -474278,13 +476110,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -474436,10 +476269,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -475042,41 +476876,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -475140,43 +476974,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -475274,7 +477109,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -475444,16 +477280,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -475556,51 +477393,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -475976,22 +477814,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -476090,13 +477929,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -476248,10 +478088,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -476854,41 +478695,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -476952,43 +478793,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -477086,7 +478928,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -477256,16 +479099,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -477368,51 +479212,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -477788,22 +479633,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -477902,13 +479748,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -478060,10 +479907,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -478666,41 +480514,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -478764,43 +480612,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -478898,7 +480747,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -479068,16 +480918,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -479180,51 +481031,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -479600,22 +481452,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -479714,13 +481567,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -479872,10 +481726,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -480478,41 +482333,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -480576,43 +482431,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -480710,7 +482566,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -480880,16 +482737,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -480992,51 +482850,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -481412,22 +483271,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -481526,13 +483386,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -481684,10 +483545,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -482290,41 +484152,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -482388,43 +484250,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -482522,7 +484385,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -482692,16 +484556,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -482804,51 +484669,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -483224,22 +485090,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -483338,13 +485205,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -483496,10 +485364,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -484102,41 +485971,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -484200,43 +486069,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -484334,7 +486204,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -484504,16 +486375,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -484616,51 +486488,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -485036,22 +486909,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -485150,13 +487024,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -485308,10 +487183,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -485914,41 +487790,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -486012,43 +487888,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -486146,7 +488023,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -486316,16 +488194,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -486428,51 +488307,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -486848,22 +488728,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -486962,13 +488843,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -487120,10 +489002,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -487726,41 +489609,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -487824,43 +489707,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -487958,7 +489842,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -488128,16 +490013,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -488240,51 +490126,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -488660,22 +490547,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -488774,13 +490662,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -488932,10 +490821,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -489538,41 +491428,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -489636,43 +491526,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -489770,7 +491661,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -489940,16 +491832,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -490052,51 +491945,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -490472,22 +492366,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -490586,13 +492481,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -490744,10 +492640,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -491350,41 +493247,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -491448,43 +493345,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -491582,7 +493480,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -491752,16 +493651,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -491864,51 +493764,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -492284,22 +494185,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -492398,13 +494300,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -492556,10 +494459,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -493162,41 +495066,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -493260,43 +495164,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -493394,7 +495299,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -493564,16 +495470,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -493676,51 +495583,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -494096,22 +496004,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -494210,13 +496119,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -494368,10 +496278,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -494974,41 +496885,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -495072,43 +496983,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -495206,7 +497118,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -495376,16 +497289,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -495488,51 +497402,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -495908,22 +497823,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -496022,13 +497938,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -496180,10 +498097,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -496786,41 +498704,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -496884,43 +498802,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -497018,7 +498937,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -497188,16 +499108,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -497300,51 +499221,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -497720,22 +499642,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -497834,13 +499757,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -497992,10 +499916,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -498598,41 +500523,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -498696,43 +500621,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -498830,7 +500756,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -499000,16 +500927,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -499112,51 +501040,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -499532,22 +501461,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -499646,13 +501576,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -499804,10 +501735,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -500410,41 +502342,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -500508,43 +502440,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -500642,7 +502575,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -500812,16 +502746,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -500924,51 +502859,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -501344,22 +503280,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -501458,13 +503395,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -501616,10 +503554,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -502222,41 +504161,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -502320,43 +504259,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -502454,7 +504394,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -502624,16 +504565,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -502736,51 +504678,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -503156,22 +505099,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -503270,13 +505214,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -503428,10 +505373,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -504034,41 +505980,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -504132,43 +506078,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -504266,7 +506213,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -504436,16 +506384,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -504548,51 +506497,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -504968,22 +506918,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -505082,13 +507033,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -505240,10 +507192,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -505846,41 +507799,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -505944,43 +507897,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -506078,7 +508032,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -506248,16 +508203,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -506360,51 +508316,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -506780,22 +508737,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -506894,13 +508852,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -507052,10 +509011,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -507658,41 +509618,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -507756,43 +509716,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -507890,7 +509851,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -508060,16 +510022,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -508172,51 +510135,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -508592,22 +510556,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -508706,13 +510671,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -508864,10 +510830,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -509470,41 +511437,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -509568,43 +511535,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -509702,7 +511670,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -509872,16 +511841,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -509984,51 +511954,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -510404,22 +512375,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -510518,13 +512490,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -510676,10 +512649,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -511282,41 +513256,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -511380,43 +513354,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -511514,7 +513489,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -511684,16 +513660,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -511796,51 +513773,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -512216,22 +514194,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -512330,13 +514309,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -512488,10 +514468,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -513094,41 +515075,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -513192,43 +515173,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -513326,7 +515308,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -513496,16 +515479,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -513608,51 +515592,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -514028,22 +516013,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -514142,13 +516128,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -514300,10 +516287,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -514906,41 +516894,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -515004,43 +516992,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -515138,7 +517127,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -515308,16 +517298,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -515420,51 +517411,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -515840,22 +517832,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -515954,13 +517947,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -516112,10 +518106,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -516718,41 +518713,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -516816,43 +518811,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -516950,7 +518946,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -517120,16 +519117,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -517232,51 +519230,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -517652,22 +519651,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -517766,13 +519766,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -517924,10 +519925,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -518530,41 +520532,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -518628,43 +520630,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -518762,7 +520765,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -518932,16 +520936,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -519044,51 +521049,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -519464,22 +521470,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -519578,13 +521585,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -519736,10 +521744,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -520342,41 +522351,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -520440,43 +522449,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -520574,7 +522584,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -520744,16 +522755,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -520856,51 +522868,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -521276,22 +523289,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -521390,13 +523404,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -521548,10 +523563,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -522154,41 +524170,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -522252,43 +524268,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -522386,7 +524403,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -522556,16 +524574,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -522668,51 +524687,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -523088,22 +525108,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -523202,13 +525223,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -523360,10 +525382,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -523966,41 +525989,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -524064,43 +526087,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -524198,7 +526222,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -524368,16 +526393,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -524480,51 +526506,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -524900,22 +526927,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -525014,13 +527042,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -525172,10 +527201,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -525778,41 +527808,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -525876,43 +527906,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -526010,7 +528041,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -526180,16 +528212,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -526292,51 +528325,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -526712,22 +528746,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -526826,13 +528861,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -526984,10 +529020,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -527590,41 +529627,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -527688,43 +529725,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -527822,7 +529860,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -527992,16 +530031,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -528104,51 +530144,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -528524,22 +530565,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -528638,13 +530680,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -528796,10 +530839,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -529402,41 +531446,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -529500,43 +531544,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -529634,7 +531679,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -529804,16 +531850,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -529916,51 +531963,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -530336,22 +532384,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -530450,13 +532499,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -530608,10 +532658,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -531214,41 +533265,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -531312,43 +533363,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -531446,7 +533498,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -531616,16 +533669,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -531728,51 +533782,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -532148,22 +534203,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -532262,13 +534318,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -532420,10 +534477,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -533026,41 +535084,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -533124,43 +535182,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -533258,7 +535317,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -533428,16 +535488,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -533540,51 +535601,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -533960,22 +536022,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -534074,13 +536137,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -534232,10 +536296,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -534838,41 +536903,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -534936,43 +537001,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -535070,7 +537136,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -535240,16 +537307,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -535352,51 +537420,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -535772,22 +537841,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -535886,13 +537956,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -536044,10 +538115,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -536650,41 +538722,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -536748,43 +538820,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -536882,7 +538955,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -537052,16 +539126,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -537164,51 +539239,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -537584,22 +539660,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -537698,13 +539775,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -537856,10 +539934,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -538462,41 +540541,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -538560,43 +540639,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -538694,7 +540774,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -538864,16 +540945,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -538976,51 +541058,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -539396,22 +541479,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -539510,13 +541594,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -539668,10 +541753,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -540274,41 +542360,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -540372,43 +542458,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -540506,7 +542593,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -540676,16 +542764,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -540788,51 +542877,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -541208,22 +543298,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -541322,13 +543413,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -541480,10 +543572,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -542086,41 +544179,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -542184,43 +544277,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -542318,7 +544412,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -542488,16 +544583,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -542600,51 +544696,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -543020,22 +545117,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -543134,13 +545232,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -543292,10 +545391,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -543898,41 +545998,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -543996,43 +546096,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -544130,7 +546231,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -544300,16 +546402,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -544412,51 +546515,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -544832,22 +546936,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -544946,13 +547051,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -545104,10 +547210,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -545710,41 +547817,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -545808,43 +547915,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -545942,7 +548050,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -546112,16 +548221,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -546224,51 +548334,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -546644,22 +548755,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -546758,13 +548870,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -546916,10 +549029,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -547522,41 +549636,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -547620,43 +549734,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -547754,7 +549869,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -547924,16 +550040,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -548036,51 +550153,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -548456,22 +550574,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -548570,13 +550689,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -548728,10 +550848,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -549334,41 +551455,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -549432,43 +551553,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -549566,7 +551688,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -549736,16 +551859,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -549848,51 +551972,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -550268,22 +552393,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -550382,13 +552508,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -550540,10 +552667,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -551146,41 +553274,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -551244,43 +553372,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -551378,7 +553507,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -551548,16 +553678,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -551660,51 +553791,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -552080,22 +554212,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -552194,13 +554327,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -552352,10 +554486,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -552958,41 +555093,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -553056,43 +555191,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -553190,7 +555326,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -553360,16 +555497,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -553472,51 +555610,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -553892,22 +556031,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -554006,13 +556146,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -554164,10 +556305,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -554770,41 +556912,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -554868,43 +557010,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -555002,7 +557145,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -555172,16 +557316,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -555284,51 +557429,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -555704,22 +557850,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -555818,13 +557965,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -555976,10 +558124,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -556582,41 +558731,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -556680,43 +558829,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -556814,7 +558964,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -556984,16 +559135,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -557096,51 +559248,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -557516,22 +559669,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -557630,13 +559784,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -557788,10 +559943,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -558394,41 +560550,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -558492,43 +560648,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -558626,7 +560783,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -558796,16 +560954,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -558908,51 +561067,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -559328,22 +561488,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -559442,13 +561603,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -559600,10 +561762,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -560206,41 +562369,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -560304,43 +562467,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -560438,7 +562602,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -560608,16 +562773,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -560720,51 +562886,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -561140,22 +563307,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -561254,13 +563422,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -561412,10 +563581,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -562018,41 +564188,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -562116,43 +564286,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -562250,7 +564421,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -562420,16 +564592,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -562532,51 +564705,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -562952,22 +565126,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -563066,13 +565241,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -563224,10 +565400,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -563830,41 +566007,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -563928,43 +566105,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -564062,7 +566240,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -564232,16 +566411,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -564344,51 +566524,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -564764,22 +566945,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -564878,13 +567060,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -565036,10 +567219,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -565642,41 +567826,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -565740,43 +567924,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -565874,7 +568059,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -566044,16 +568230,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -566156,51 +568343,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -566576,22 +568764,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -566690,13 +568879,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -566848,10 +569038,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -567454,41 +569645,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -567552,43 +569743,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -567686,7 +569878,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -567856,16 +570049,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -567968,51 +570162,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -568388,22 +570583,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -568502,13 +570698,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -568660,10 +570857,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -569266,41 +571464,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -569364,43 +571562,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -569498,7 +571697,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -569668,16 +571868,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -569780,51 +571981,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -570200,22 +572402,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -570314,13 +572517,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -570472,10 +572676,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -571078,41 +573283,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -571176,43 +573381,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -571310,7 +573516,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -571480,16 +573687,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -571592,51 +573800,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -572012,22 +574221,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -572126,13 +574336,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -572284,10 +574495,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -572890,41 +575102,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -572988,43 +575200,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -573122,7 +575335,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -573292,16 +575506,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -573404,51 +575619,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -573824,22 +576040,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -573938,13 +576155,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -574096,10 +576314,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -574702,41 +576921,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -574800,43 +577019,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -574934,7 +577154,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -575104,16 +577325,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -575216,51 +577438,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -575636,22 +577859,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -575750,13 +577974,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -575908,10 +578133,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -576514,41 +578740,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -576612,43 +578838,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -576746,7 +578973,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -576916,16 +579144,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -577028,51 +579257,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -577448,22 +579678,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -577562,13 +579793,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -577720,10 +579952,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -578326,41 +580559,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -578424,43 +580657,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -578558,7 +580792,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -578728,16 +580963,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -578840,51 +581076,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -579260,22 +581497,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -579374,13 +581612,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -579532,10 +581771,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -580138,41 +582378,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -580236,43 +582476,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -580370,7 +582611,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -580540,16 +582782,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -580652,51 +582895,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -581072,22 +583316,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -581186,13 +583431,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -581344,10 +583590,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -581950,41 +584197,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -582048,43 +584295,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -582182,7 +584430,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -582352,16 +584601,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -582464,51 +584714,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -582884,22 +585135,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -582998,13 +585250,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -583156,10 +585409,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -583762,41 +586016,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -583860,43 +586114,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -583994,7 +586249,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -584164,16 +586420,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -584276,51 +586533,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -584696,22 +586954,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -584810,13 +587069,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -584968,10 +587228,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -585574,41 +587835,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -585672,43 +587933,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -585806,7 +588068,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -585976,16 +588239,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -586088,51 +588352,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -586508,22 +588773,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -586622,13 +588888,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -586780,10 +589047,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -587386,41 +589654,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -587484,43 +589752,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -587618,7 +589887,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -587788,16 +590058,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -587900,51 +590171,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -588320,22 +590592,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -588434,13 +590707,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -588592,10 +590866,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -589198,41 +591473,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -589296,43 +591571,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -589430,7 +591706,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -589600,16 +591877,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -589712,51 +591990,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -590132,22 +592411,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -590246,13 +592526,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -590404,10 +592685,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -591010,41 +593292,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -591108,43 +593390,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -591242,7 +593525,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -591412,16 +593696,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -591524,51 +593809,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -591944,22 +594230,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -592058,13 +594345,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -592216,10 +594504,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -592822,41 +595111,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -592920,43 +595209,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -593054,7 +595344,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -593224,16 +595515,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -593336,51 +595628,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -593756,22 +596049,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -593870,13 +596164,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -594028,10 +596323,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -594634,41 +596930,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -594732,43 +597028,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -594866,7 +597163,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -595036,16 +597334,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -595148,51 +597447,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -595568,22 +597868,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -595682,13 +597983,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -595840,10 +598142,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -596446,41 +598749,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -596544,43 +598847,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -596678,7 +598982,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -596848,16 +599153,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -596960,51 +599266,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -597380,22 +599687,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -597494,13 +599802,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -597652,10 +599961,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -598258,41 +600568,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -598356,43 +600666,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -598490,7 +600801,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -598660,16 +600972,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -598772,51 +601085,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -599192,22 +601506,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -599306,13 +601621,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -599464,10 +601780,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -600070,41 +602387,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -600168,43 +602485,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -600302,7 +602620,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -600472,16 +602791,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -600584,51 +602904,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -601004,22 +603325,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -601118,13 +603440,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -601276,10 +603599,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -601882,41 +604206,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -601980,43 +604304,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -602114,7 +604439,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -602284,16 +604610,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -602396,51 +604723,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -602816,22 +605144,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -602930,13 +605259,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -603088,10 +605418,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -603694,41 +606025,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -603792,43 +606123,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -603926,7 +606258,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -604096,16 +606429,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -604208,51 +606542,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -604628,22 +606963,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -604742,13 +607078,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -604900,10 +607237,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -605506,41 +607844,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -605604,43 +607942,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -605738,7 +608077,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -605908,16 +608248,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -606020,51 +608361,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -606440,22 +608782,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -606554,13 +608897,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -606712,10 +609056,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -607318,41 +609663,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -607416,43 +609761,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -607550,7 +609896,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -607720,16 +610067,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -607832,51 +610180,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -608252,22 +610601,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -608366,13 +610716,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -608524,10 +610875,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -609130,41 +611482,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -609228,43 +611580,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -609362,7 +611715,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -609532,16 +611886,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -609644,51 +611999,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -610064,22 +612420,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -610178,13 +612535,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -610336,10 +612694,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -610942,41 +613301,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -611040,43 +613399,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -611174,7 +613534,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -611344,16 +613705,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -611456,51 +613818,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -611876,22 +614239,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -611990,13 +614354,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -612148,10 +614513,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -612754,41 +615120,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -612852,43 +615218,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -612986,7 +615353,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -613156,16 +615524,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -613268,51 +615637,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -613688,22 +616058,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -613802,13 +616173,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -613960,10 +616332,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -614566,41 +616939,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -614664,43 +617037,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -614798,7 +617172,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -614968,16 +617343,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -615080,51 +617456,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -615500,22 +617877,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -615614,13 +617992,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -615772,10 +618151,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -616378,41 +618758,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -616476,43 +618856,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -616610,7 +618991,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -616780,16 +619162,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -616892,51 +619275,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -617312,22 +619696,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -617426,13 +619811,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -617584,10 +619970,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -618190,41 +620577,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -618288,43 +620675,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -618422,7 +620810,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -618592,16 +620981,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -618704,51 +621094,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -619124,22 +621515,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -619238,13 +621630,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -619396,10 +621789,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -620002,41 +622396,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -620100,43 +622494,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -620234,7 +622629,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -620404,16 +622800,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -620516,51 +622913,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -620936,22 +623334,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -621050,13 +623449,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -621208,10 +623608,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -621814,41 +624215,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -621912,43 +624313,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -622046,7 +624448,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -622216,16 +624619,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -622328,51 +624732,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -622748,22 +625153,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -622862,13 +625268,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -623020,10 +625427,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -623626,41 +626034,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -623724,43 +626132,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -623858,7 +626267,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -624028,16 +626438,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -624140,51 +626551,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -624560,22 +626972,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -624674,13 +627087,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -624832,10 +627246,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -625438,41 +627853,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -625536,43 +627951,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -625670,7 +628086,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -625840,16 +628257,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -625952,51 +628370,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -626372,22 +628791,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -626486,13 +628906,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -626644,10 +629065,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -627250,41 +629672,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -627348,43 +629770,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -627482,7 +629905,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -627652,16 +630076,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -627764,51 +630189,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -628184,22 +630610,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -628298,13 +630725,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -628456,10 +630884,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -629062,41 +631491,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -629160,43 +631589,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -629294,7 +631724,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -629464,16 +631895,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -629576,51 +632008,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -629996,22 +632429,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -630110,13 +632544,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -630268,10 +632703,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -630874,41 +633310,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -630972,43 +633408,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -631106,7 +633543,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -631276,16 +633714,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -631388,51 +633827,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -631808,22 +634248,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -631922,13 +634363,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -632080,10 +634522,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -632686,41 +635129,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -632784,43 +635227,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -632918,7 +635362,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -633088,16 +635533,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -633200,51 +635646,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -633620,22 +636067,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -633734,13 +636182,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -633892,10 +636341,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -634498,41 +636948,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -634596,43 +637046,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -634730,7 +637181,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -634900,16 +637352,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -635012,51 +637465,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -635432,22 +637886,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -635546,13 +638001,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -635704,10 +638160,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -636310,41 +638767,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -636408,43 +638865,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -636542,7 +639000,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -636712,16 +639171,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -636824,51 +639284,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -637244,22 +639705,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -637358,13 +639820,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -637516,10 +639979,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -638122,41 +640586,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -638220,43 +640684,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -638354,7 +640819,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -638524,16 +640990,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -638636,51 +641103,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -639056,22 +641524,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -639170,13 +641639,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -639328,10 +641798,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -639934,41 +642405,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -640032,43 +642503,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -640166,7 +642638,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -640336,16 +642809,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -640448,51 +642922,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -640868,22 +643343,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -640982,13 +643458,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -641140,10 +643617,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -641746,41 +644224,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -641844,43 +644322,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -641978,7 +644457,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -642148,16 +644628,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -642260,51 +644741,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -642680,22 +645162,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -642794,13 +645277,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -642952,10 +645436,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -643558,41 +646043,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -643656,43 +646141,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -643790,7 +646276,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -643960,16 +646447,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -644072,51 +646560,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -644492,22 +646981,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -644606,13 +647096,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -644764,10 +647255,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -645370,41 +647862,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -645468,43 +647960,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -645602,7 +648095,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -645772,16 +648266,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -645884,51 +648379,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -646304,22 +648800,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -646418,13 +648915,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -646576,10 +649074,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -647182,41 +649681,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -647280,43 +649779,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -647414,7 +649914,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -647584,16 +650085,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -647696,51 +650198,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -648116,22 +650619,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -648230,13 +650734,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -648388,10 +650893,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -648994,41 +651500,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -649092,43 +651598,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -649226,7 +651733,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -649396,16 +651904,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -649508,51 +652017,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -649928,22 +652438,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -650042,13 +652553,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -650200,10 +652712,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -650806,41 +653319,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -650904,43 +653417,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -651038,7 +653552,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -651208,16 +653723,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -651320,51 +653836,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -651740,22 +654257,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -651854,13 +654372,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -652012,10 +654531,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -652618,41 +655138,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -652716,43 +655236,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -652850,7 +655371,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -653020,16 +655542,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -653132,51 +655655,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -653552,22 +656076,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -653666,13 +656191,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -653824,10 +656350,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -654430,41 +656957,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -654528,43 +657055,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -654662,7 +657190,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -654832,16 +657361,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -654944,51 +657474,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -655364,22 +657895,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -655478,13 +658010,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -655636,10 +658169,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -656242,41 +658776,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -656340,43 +658874,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -656474,7 +659009,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -656644,16 +659180,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -656756,51 +659293,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -657176,22 +659714,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -657290,13 +659829,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -657448,10 +659988,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -658054,41 +660595,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -658152,43 +660693,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -658286,7 +660828,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -658456,16 +660999,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -658568,51 +661112,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -658988,22 +661533,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -659102,13 +661648,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -659260,10 +661807,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -659866,41 +662414,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -659964,43 +662512,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -660098,7 +662647,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -660268,16 +662818,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -660380,51 +662931,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -660800,22 +663352,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -660914,13 +663467,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -661072,10 +663626,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -661678,41 +664233,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -661776,43 +664331,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -661910,7 +664466,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -662080,16 +664637,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -662192,51 +664750,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -662612,22 +665171,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -662726,13 +665286,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -662884,10 +665445,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -663490,41 +666052,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -663588,43 +666150,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -663722,7 +666285,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -663892,16 +666456,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -664004,51 +666569,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -664424,22 +666990,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -664538,13 +667105,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -664696,10 +667264,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -665302,41 +667871,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -665400,43 +667969,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -665534,7 +668104,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -665704,16 +668275,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -665816,51 +668388,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -666236,22 +668809,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -666350,13 +668924,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -666508,10 +669083,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -667114,41 +669690,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -667212,43 +669788,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -667346,7 +669923,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -667516,16 +670094,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -667628,51 +670207,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -668048,22 +670628,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -668162,13 +670743,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -668320,10 +670902,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -668926,41 +671509,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -669024,43 +671607,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -669158,7 +671742,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -669328,16 +671913,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -669440,51 +672026,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -669860,22 +672447,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -669974,13 +672562,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -670132,10 +672721,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -670738,41 +673328,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -670836,43 +673426,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -670970,7 +673561,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -671140,16 +673732,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -671252,51 +673845,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -671672,22 +674266,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -671786,13 +674381,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -671944,10 +674540,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -672550,41 +675147,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -672648,43 +675245,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -672782,7 +675380,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -672952,16 +675551,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -673064,51 +675664,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -673484,22 +676085,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -673598,13 +676200,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -673756,10 +676359,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -674362,41 +676966,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -674460,43 +677064,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -674594,7 +677199,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -674764,16 +677370,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -674876,51 +677483,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -675296,22 +677904,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -675410,13 +678019,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -675568,10 +678178,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -676174,41 +678785,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -676272,43 +678883,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -676406,7 +679018,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -676576,16 +679189,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -676688,51 +679302,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -677108,22 +679723,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -677222,13 +679838,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -677380,10 +679997,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -677986,41 +680604,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -678084,43 +680702,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -678218,7 +680837,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -678388,16 +681008,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -678500,51 +681121,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -678920,22 +681542,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -679034,13 +681657,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -679192,10 +681816,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -679798,41 +682423,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -679896,43 +682521,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -680030,7 +682656,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -680200,16 +682827,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -680312,51 +682940,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -680732,22 +683361,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -680846,13 +683476,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -681004,10 +683635,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -681610,41 +684242,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -681708,43 +684340,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -681842,7 +684475,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -682012,16 +684646,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -682124,51 +684759,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -682544,22 +685180,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -682658,13 +685295,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -682816,10 +685454,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -683422,41 +686061,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -683520,43 +686159,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -683654,7 +686294,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -683824,16 +686465,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -683936,51 +686578,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -684356,22 +686999,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -684470,13 +687114,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -684628,10 +687273,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" @@ -685234,41 +687880,41 @@ "T1546.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/screensaver_event_trigger_execution.yml","1" "T1148","No","-","0" "T1593.001","No","-","0" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","71" -"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","71" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_ldap_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_writing_dynamicwrapperx.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ms_scripting_process_loading_wmi_module.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/vbscript_execution_using_wscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/jscript_execution_using_cscript_app.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell___connect_to_internet_with_hidden_window.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_with_discord_dns_query.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml","72" +"T1059","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_outbound_ldap_traffic.yml","72" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/domain_account_discovery_with_net_app.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell_script_block.yml","17" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/get_aduser_with_powershell.yml","17" @@ -685332,43 +687978,44 @@ "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1568","No","-","0" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","37" -"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","37" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_raccine_scheduled_task_deletion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","38" +"T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","38" "T1499.002","No","-","0" "T1556.001","No","-","0" "T1052.001","No","-","0" @@ -685466,7 +688113,8 @@ "T1571","No","-","0" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1003.007","No","-","0" -"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","2" +"T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","2" "T1073","No","-","0" "T1137.003","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","18" @@ -685636,16 +688284,17 @@ "T1548.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_sudoers_tmp_file_creation.yml","7" "T1149","No","-","0" "T1110.004","No","-","0" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","12" -"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","12" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/linux_change_file_owner_to_root.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml","14" +"T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","14" "T1564.007","No","-","0" "T1001","No","-","0" "T1555.002","No","-","0" @@ -685748,51 +688397,52 @@ "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","92" -"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","92" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/firewall_allowed_program_enable.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_defender_exclusion_registry_entry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_mpengine_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/etw_registry_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_spynet_reporting.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remove_windows_defender_directory.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_dism_remove_defender.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_blockatfirstseen_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/add_or_set_windows_defender_exclusion.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_windows_defender_exclusion_commands.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_antivirus_registry.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_defender_services.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_enhanced_notification.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmic_noninteractive_app_uninstallation.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_schedule_task.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_defender_submit_samples_consent_feature.yml","94" +"T1562","Yes","https://github.com/splunk/security_content/blob/develop/experimental/ssa___disable_defender_antivirus_registry.yml","94" "T1096","No","-","0" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_file_deletion_in_windefender_folder.yml","6" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","6" @@ -686168,22 +688818,23 @@ "T1558.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","1" "T1574.012","No","-","0" "T1591.001","No","-","0" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","27" -"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","27" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","29" +"T1070","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml","29" "T1584.004","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","12" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","12" @@ -686282,13 +688933,14 @@ "T1487","No","-","0" "T1583.006","No","-","0" "T1587.004","No","-","0" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","7" -"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","7" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_carry_out_string_command_parameter.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/potentially_malicious_code_on_commandline.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","8" +"T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","8" "T1480.001","No","-","0" "T1137.001","No","-","0" "T1028","No","-","0" @@ -686440,10 +689092,11 @@ "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshtml_module_load_in_office_product.yml","21" "T1494","No","-","0" "T1170","No","-","0" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","4" -"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","4" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___sdelete_application_execution.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","5" +"T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml","5" "T1166","No","-","0" "T1527","No","-","0" "T1546.013","No","-","0" diff --git a/docs/mitre-map/coverage.json b/docs/mitre-map/coverage.json index 6e3d7cc673..c4b87392b4 100644 --- a/docs/mitre-map/coverage.json +++ b/docs/mitre-map/coverage.json @@ -332,7 +332,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -403,8 +403,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -476,8 +476,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -631,8 +631,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -723,8 +723,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -1113,8 +1113,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -1179,8 +1179,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -1290,8 +1290,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -1879,7 +1879,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -1950,8 +1950,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -2023,8 +2023,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -2178,8 +2178,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -2270,8 +2270,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -2660,8 +2660,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -2726,8 +2726,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -2837,8 +2837,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -3426,7 +3426,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -3497,8 +3497,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -3570,8 +3570,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -3725,8 +3725,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -3817,8 +3817,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -4207,8 +4207,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -4273,8 +4273,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -4384,8 +4384,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -4973,7 +4973,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -5044,8 +5044,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -5117,8 +5117,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -5272,8 +5272,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -5364,8 +5364,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -5754,8 +5754,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -5820,8 +5820,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -5931,8 +5931,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -6520,7 +6520,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -6591,8 +6591,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -6664,8 +6664,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -6819,8 +6819,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -6911,8 +6911,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -7301,8 +7301,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -7367,8 +7367,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -7478,8 +7478,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -8067,7 +8067,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -8138,8 +8138,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -8211,8 +8211,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -8366,8 +8366,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -8458,8 +8458,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -8848,8 +8848,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -8914,8 +8914,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -9025,8 +9025,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -9614,7 +9614,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -9685,8 +9685,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -9758,8 +9758,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -9913,8 +9913,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -10005,8 +10005,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -10395,8 +10395,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -10461,8 +10461,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -10572,8 +10572,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -11161,7 +11161,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -11232,8 +11232,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -11305,8 +11305,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -11460,8 +11460,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -11552,8 +11552,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -11942,8 +11942,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -12008,8 +12008,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -12119,8 +12119,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -12708,7 +12708,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -12779,8 +12779,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -12852,8 +12852,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -13007,8 +13007,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -13099,8 +13099,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -13489,8 +13489,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -13555,8 +13555,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -13666,8 +13666,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -14255,7 +14255,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -14326,8 +14326,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -14399,8 +14399,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -14554,8 +14554,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -14646,8 +14646,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -15036,8 +15036,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -15102,8 +15102,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -15213,8 +15213,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -15802,7 +15802,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -15873,8 +15873,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -15946,8 +15946,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -16101,8 +16101,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -16193,8 +16193,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -16583,8 +16583,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -16649,8 +16649,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -16760,8 +16760,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -17349,7 +17349,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -17420,8 +17420,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -17493,8 +17493,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -17648,8 +17648,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -17740,8 +17740,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -18130,8 +18130,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -18196,8 +18196,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -18307,8 +18307,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -18896,7 +18896,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -18967,8 +18967,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -19040,8 +19040,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -19195,8 +19195,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -19287,8 +19287,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -19677,8 +19677,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -19743,8 +19743,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -19854,8 +19854,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -20443,7 +20443,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -20514,8 +20514,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -20587,8 +20587,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -20742,8 +20742,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -20834,8 +20834,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -21224,8 +21224,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -21290,8 +21290,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -21401,8 +21401,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -21990,7 +21990,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -22061,8 +22061,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -22134,8 +22134,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -22289,8 +22289,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -22381,8 +22381,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -22771,8 +22771,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -22837,8 +22837,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -22948,8 +22948,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -23537,7 +23537,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -23608,8 +23608,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -23681,8 +23681,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -23836,8 +23836,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -23928,8 +23928,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -24318,8 +24318,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -24384,8 +24384,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -24495,8 +24495,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -25084,7 +25084,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -25155,8 +25155,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -25228,8 +25228,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -25383,8 +25383,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -25475,8 +25475,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -25865,8 +25865,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -25931,8 +25931,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -26042,8 +26042,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -26631,7 +26631,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -26702,8 +26702,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -26775,8 +26775,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -26930,8 +26930,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -27022,8 +27022,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -27412,8 +27412,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -27478,8 +27478,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -27589,8 +27589,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -28178,7 +28178,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -28249,8 +28249,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -28322,8 +28322,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -28477,8 +28477,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -28569,8 +28569,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -28959,8 +28959,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -29025,8 +29025,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -29136,8 +29136,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -29725,7 +29725,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -29796,8 +29796,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -29869,8 +29869,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -30024,8 +30024,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -30116,8 +30116,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -30506,8 +30506,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -30572,8 +30572,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -30683,8 +30683,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -31272,7 +31272,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -31343,8 +31343,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -31416,8 +31416,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -31571,8 +31571,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -31663,8 +31663,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -32053,8 +32053,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -32119,8 +32119,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -32230,8 +32230,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -32819,7 +32819,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -32890,8 +32890,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -32963,8 +32963,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -33118,8 +33118,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -33210,8 +33210,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -33600,8 +33600,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -33666,8 +33666,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -33777,8 +33777,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -34366,7 +34366,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -34437,8 +34437,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -34510,8 +34510,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -34665,8 +34665,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -34757,8 +34757,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -35147,8 +35147,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -35213,8 +35213,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -35324,8 +35324,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -35913,7 +35913,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -35984,8 +35984,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -36057,8 +36057,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -36212,8 +36212,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -36304,8 +36304,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -36694,8 +36694,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -36760,8 +36760,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -36871,8 +36871,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -37460,7 +37460,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -37531,8 +37531,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -37604,8 +37604,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -37759,8 +37759,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -37851,8 +37851,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -38241,8 +38241,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -38307,8 +38307,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -38418,8 +38418,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -39007,7 +39007,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -39078,8 +39078,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -39151,8 +39151,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -39306,8 +39306,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -39398,8 +39398,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -39788,8 +39788,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -39854,8 +39854,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -39965,8 +39965,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -40554,7 +40554,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -40625,8 +40625,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -40698,8 +40698,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -40853,8 +40853,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -40945,8 +40945,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -41335,8 +41335,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -41401,8 +41401,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -41512,8 +41512,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -42101,7 +42101,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -42172,8 +42172,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -42245,8 +42245,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -42400,8 +42400,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -42492,8 +42492,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -42882,8 +42882,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -42948,8 +42948,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -43059,8 +43059,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -43648,7 +43648,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -43719,8 +43719,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -43792,8 +43792,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -43947,8 +43947,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -44039,8 +44039,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -44429,8 +44429,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -44495,8 +44495,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -44606,8 +44606,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -45195,7 +45195,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -45266,8 +45266,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -45339,8 +45339,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -45494,8 +45494,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -45586,8 +45586,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -45976,8 +45976,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -46042,8 +46042,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -46153,8 +46153,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -46742,7 +46742,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -46813,8 +46813,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -46886,8 +46886,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -47041,8 +47041,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -47133,8 +47133,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -47523,8 +47523,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -47589,8 +47589,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -47700,8 +47700,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -48289,7 +48289,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -48360,8 +48360,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -48433,8 +48433,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -48588,8 +48588,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -48680,8 +48680,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -49070,8 +49070,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -49136,8 +49136,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -49247,8 +49247,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -49836,7 +49836,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -49907,8 +49907,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -49980,8 +49980,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -50135,8 +50135,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -50227,8 +50227,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -50617,8 +50617,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -50683,8 +50683,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -50794,8 +50794,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -51383,7 +51383,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -51454,8 +51454,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -51527,8 +51527,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -51682,8 +51682,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -51774,8 +51774,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -52164,8 +52164,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -52230,8 +52230,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -52341,8 +52341,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -52930,7 +52930,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -53001,8 +53001,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -53074,8 +53074,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -53229,8 +53229,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -53321,8 +53321,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -53711,8 +53711,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -53777,8 +53777,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -53888,8 +53888,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -54477,7 +54477,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -54548,8 +54548,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -54621,8 +54621,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -54776,8 +54776,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -54868,8 +54868,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -55258,8 +55258,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -55324,8 +55324,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -55435,8 +55435,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -56024,7 +56024,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -56095,8 +56095,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -56168,8 +56168,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -56323,8 +56323,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -56415,8 +56415,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -56805,8 +56805,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -56871,8 +56871,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -56982,8 +56982,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -57571,7 +57571,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -57642,8 +57642,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -57715,8 +57715,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -57870,8 +57870,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -57962,8 +57962,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -58352,8 +58352,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -58418,8 +58418,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -58529,8 +58529,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -59118,7 +59118,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -59189,8 +59189,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -59262,8 +59262,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -59417,8 +59417,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -59509,8 +59509,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -59899,8 +59899,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -59965,8 +59965,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -60076,8 +60076,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -60665,7 +60665,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -60736,8 +60736,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -60809,8 +60809,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -60964,8 +60964,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -61056,8 +61056,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -61446,8 +61446,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -61512,8 +61512,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -61623,8 +61623,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -62212,7 +62212,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -62283,8 +62283,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -62356,8 +62356,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -62511,8 +62511,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -62603,8 +62603,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -62993,8 +62993,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -63059,8 +63059,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -63170,8 +63170,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -63759,7 +63759,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -63830,8 +63830,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -63903,8 +63903,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -64058,8 +64058,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -64150,8 +64150,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -64540,8 +64540,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -64606,8 +64606,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -64717,8 +64717,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -65306,7 +65306,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -65377,8 +65377,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -65450,8 +65450,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -65605,8 +65605,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -65697,8 +65697,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -66087,8 +66087,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -66153,8 +66153,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -66264,8 +66264,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -66853,7 +66853,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -66924,8 +66924,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -66997,8 +66997,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -67152,8 +67152,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -67244,8 +67244,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -67634,8 +67634,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -67700,8 +67700,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -67811,8 +67811,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -68400,7 +68400,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -68471,8 +68471,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -68544,8 +68544,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -68699,8 +68699,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -68791,8 +68791,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -69181,8 +69181,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -69247,8 +69247,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -69358,8 +69358,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -69947,7 +69947,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -70018,8 +70018,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -70091,8 +70091,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -70246,8 +70246,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -70338,8 +70338,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -70728,8 +70728,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -70794,8 +70794,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -70905,8 +70905,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -71494,7 +71494,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -71565,8 +71565,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -71638,8 +71638,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -71793,8 +71793,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -71885,8 +71885,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -72275,8 +72275,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -72341,8 +72341,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -72452,8 +72452,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -73041,7 +73041,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -73112,8 +73112,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -73185,8 +73185,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -73340,8 +73340,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -73432,8 +73432,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -73822,8 +73822,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -73888,8 +73888,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -73999,8 +73999,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -74588,7 +74588,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -74659,8 +74659,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -74732,8 +74732,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -74887,8 +74887,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -74979,8 +74979,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -75369,8 +75369,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -75435,8 +75435,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -75546,8 +75546,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -76135,7 +76135,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -76206,8 +76206,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -76279,8 +76279,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -76434,8 +76434,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -76526,8 +76526,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -76916,8 +76916,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -76982,8 +76982,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -77093,8 +77093,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -77682,7 +77682,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -77753,8 +77753,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -77826,8 +77826,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -77981,8 +77981,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -78073,8 +78073,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -78463,8 +78463,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -78529,8 +78529,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -78640,8 +78640,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -79229,7 +79229,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -79300,8 +79300,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -79373,8 +79373,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -79528,8 +79528,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -79620,8 +79620,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -80010,8 +80010,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -80076,8 +80076,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -80187,8 +80187,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -80776,7 +80776,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -80847,8 +80847,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -80920,8 +80920,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -81075,8 +81075,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -81167,8 +81167,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -81557,8 +81557,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -81623,8 +81623,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -81734,8 +81734,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -82323,7 +82323,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -82394,8 +82394,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -82467,8 +82467,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -82622,8 +82622,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -82714,8 +82714,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -83104,8 +83104,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -83170,8 +83170,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -83281,8 +83281,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -83870,7 +83870,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -83941,8 +83941,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -84014,8 +84014,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -84169,8 +84169,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -84261,8 +84261,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -84651,8 +84651,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -84717,8 +84717,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -84828,8 +84828,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -85417,7 +85417,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -85488,8 +85488,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -85561,8 +85561,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -85716,8 +85716,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -85808,8 +85808,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -86198,8 +86198,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -86264,8 +86264,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -86375,8 +86375,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -86964,7 +86964,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -87035,8 +87035,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -87108,8 +87108,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -87263,8 +87263,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -87355,8 +87355,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -87745,8 +87745,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -87811,8 +87811,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -87922,8 +87922,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -88511,7 +88511,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -88582,8 +88582,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -88655,8 +88655,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -88810,8 +88810,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -88902,8 +88902,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -89292,8 +89292,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -89358,8 +89358,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -89469,8 +89469,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -90058,7 +90058,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -90129,8 +90129,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -90202,8 +90202,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -90357,8 +90357,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -90449,8 +90449,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -90839,8 +90839,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -90905,8 +90905,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -91016,8 +91016,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -91605,7 +91605,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -91676,8 +91676,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -91749,8 +91749,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -91904,8 +91904,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -91996,8 +91996,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -92386,8 +92386,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -92452,8 +92452,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -92563,8 +92563,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -93152,7 +93152,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -93223,8 +93223,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -93296,8 +93296,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -93451,8 +93451,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -93543,8 +93543,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -93933,8 +93933,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -93999,8 +93999,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -94110,8 +94110,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -94699,7 +94699,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -94770,8 +94770,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -94843,8 +94843,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -94998,8 +94998,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -95090,8 +95090,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -95480,8 +95480,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -95546,8 +95546,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -95657,8 +95657,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -96246,7 +96246,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -96317,8 +96317,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -96390,8 +96390,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -96545,8 +96545,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -96637,8 +96637,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -97027,8 +97027,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -97093,8 +97093,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -97204,8 +97204,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -97793,7 +97793,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -97864,8 +97864,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -97937,8 +97937,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -98092,8 +98092,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -98184,8 +98184,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -98574,8 +98574,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -98640,8 +98640,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -98751,8 +98751,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -99340,7 +99340,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -99411,8 +99411,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -99484,8 +99484,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -99639,8 +99639,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -99731,8 +99731,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -100121,8 +100121,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -100187,8 +100187,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -100298,8 +100298,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -100887,7 +100887,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -100958,8 +100958,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -101031,8 +101031,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -101186,8 +101186,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -101278,8 +101278,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -101668,8 +101668,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -101734,8 +101734,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -101845,8 +101845,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -102434,7 +102434,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -102505,8 +102505,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -102578,8 +102578,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -102733,8 +102733,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -102825,8 +102825,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -103215,8 +103215,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -103281,8 +103281,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -103392,8 +103392,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -103981,7 +103981,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -104052,8 +104052,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -104125,8 +104125,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -104280,8 +104280,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -104372,8 +104372,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -104762,8 +104762,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -104828,8 +104828,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -104939,8 +104939,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -105528,7 +105528,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -105599,8 +105599,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -105672,8 +105672,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -105827,8 +105827,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -105919,8 +105919,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -106309,8 +106309,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -106375,8 +106375,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -106486,8 +106486,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -107075,7 +107075,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -107146,8 +107146,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -107219,8 +107219,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -107374,8 +107374,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -107466,8 +107466,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -107856,8 +107856,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -107922,8 +107922,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -108033,8 +108033,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -108622,7 +108622,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -108693,8 +108693,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -108766,8 +108766,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -108921,8 +108921,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -109013,8 +109013,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -109403,8 +109403,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -109469,8 +109469,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -109580,8 +109580,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -110169,7 +110169,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -110240,8 +110240,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -110313,8 +110313,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -110468,8 +110468,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -110560,8 +110560,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -110950,8 +110950,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -111016,8 +111016,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -111127,8 +111127,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -111716,7 +111716,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -111787,8 +111787,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -111860,8 +111860,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -112015,8 +112015,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -112107,8 +112107,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -112497,8 +112497,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -112563,8 +112563,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -112674,8 +112674,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -113263,7 +113263,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -113334,8 +113334,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -113407,8 +113407,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -113562,8 +113562,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -113654,8 +113654,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -114044,8 +114044,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -114110,8 +114110,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -114221,8 +114221,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -114810,7 +114810,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -114881,8 +114881,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -114954,8 +114954,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -115109,8 +115109,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -115201,8 +115201,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -115591,8 +115591,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -115657,8 +115657,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -115768,8 +115768,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -116357,7 +116357,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -116428,8 +116428,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -116501,8 +116501,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -116656,8 +116656,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -116748,8 +116748,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -117138,8 +117138,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -117204,8 +117204,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -117315,8 +117315,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -117904,7 +117904,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -117975,8 +117975,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -118048,8 +118048,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -118203,8 +118203,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -118295,8 +118295,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -118685,8 +118685,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -118751,8 +118751,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -118862,8 +118862,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -119451,7 +119451,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -119522,8 +119522,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -119595,8 +119595,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -119750,8 +119750,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -119842,8 +119842,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -120232,8 +120232,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -120298,8 +120298,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -120409,8 +120409,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -120998,7 +120998,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -121069,8 +121069,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -121142,8 +121142,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -121297,8 +121297,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -121389,8 +121389,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -121779,8 +121779,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -121845,8 +121845,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -121956,8 +121956,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -122545,7 +122545,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -122616,8 +122616,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -122689,8 +122689,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -122844,8 +122844,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -122936,8 +122936,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -123326,8 +123326,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -123392,8 +123392,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -123503,8 +123503,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -124092,7 +124092,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -124163,8 +124163,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -124236,8 +124236,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -124391,8 +124391,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -124483,8 +124483,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -124873,8 +124873,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -124939,8 +124939,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -125050,8 +125050,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -125639,7 +125639,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -125710,8 +125710,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -125783,8 +125783,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -125938,8 +125938,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -126030,8 +126030,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -126420,8 +126420,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -126486,8 +126486,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -126597,8 +126597,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -127186,7 +127186,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -127257,8 +127257,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -127330,8 +127330,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -127485,8 +127485,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -127577,8 +127577,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -127967,8 +127967,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -128033,8 +128033,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -128144,8 +128144,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -128733,7 +128733,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -128804,8 +128804,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -128877,8 +128877,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -129032,8 +129032,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -129124,8 +129124,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -129514,8 +129514,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -129580,8 +129580,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -129691,8 +129691,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -130280,7 +130280,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -130351,8 +130351,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -130424,8 +130424,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -130579,8 +130579,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -130671,8 +130671,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -131061,8 +131061,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -131127,8 +131127,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -131238,8 +131238,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -131827,7 +131827,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -131898,8 +131898,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -131971,8 +131971,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -132126,8 +132126,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -132218,8 +132218,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -132608,8 +132608,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -132674,8 +132674,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -132785,8 +132785,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -133374,7 +133374,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -133445,8 +133445,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -133518,8 +133518,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -133673,8 +133673,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -133765,8 +133765,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -134155,8 +134155,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -134221,8 +134221,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -134332,8 +134332,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -134921,7 +134921,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -134992,8 +134992,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -135065,8 +135065,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -135220,8 +135220,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -135312,8 +135312,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -135702,8 +135702,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -135768,8 +135768,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -135879,8 +135879,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -136468,7 +136468,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -136539,8 +136539,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -136612,8 +136612,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -136767,8 +136767,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -136859,8 +136859,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -137249,8 +137249,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -137315,8 +137315,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -137426,8 +137426,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -138015,7 +138015,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -138086,8 +138086,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -138159,8 +138159,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -138314,8 +138314,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -138406,8 +138406,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -138796,8 +138796,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -138862,8 +138862,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -138973,8 +138973,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -139562,7 +139562,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -139633,8 +139633,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -139706,8 +139706,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -139861,8 +139861,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -139953,8 +139953,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -140343,8 +140343,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -140409,8 +140409,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -140520,8 +140520,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -141109,7 +141109,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -141180,8 +141180,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -141253,8 +141253,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -141408,8 +141408,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -141500,8 +141500,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -141890,8 +141890,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -141956,8 +141956,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -142067,8 +142067,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -142656,7 +142656,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -142727,8 +142727,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -142800,8 +142800,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -142955,8 +142955,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -143047,8 +143047,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -143437,8 +143437,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -143503,8 +143503,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -143614,8 +143614,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -144203,7 +144203,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -144274,8 +144274,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -144347,8 +144347,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -144502,8 +144502,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -144594,8 +144594,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -144984,8 +144984,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -145050,8 +145050,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -145161,8 +145161,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -145750,7 +145750,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -145821,8 +145821,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -145894,8 +145894,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -146049,8 +146049,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -146141,8 +146141,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -146531,8 +146531,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -146597,8 +146597,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -146708,8 +146708,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -147297,7 +147297,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -147368,8 +147368,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -147441,8 +147441,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -147596,8 +147596,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -147688,8 +147688,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -148078,8 +148078,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -148144,8 +148144,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -148255,8 +148255,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -148844,7 +148844,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -148915,8 +148915,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -148988,8 +148988,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -149143,8 +149143,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -149235,8 +149235,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -149625,8 +149625,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -149691,8 +149691,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -149802,8 +149802,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -150391,7 +150391,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -150462,8 +150462,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -150535,8 +150535,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -150690,8 +150690,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -150782,8 +150782,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -151172,8 +151172,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -151238,8 +151238,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -151349,8 +151349,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -151938,7 +151938,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -152009,8 +152009,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -152082,8 +152082,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -152237,8 +152237,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -152329,8 +152329,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -152719,8 +152719,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -152785,8 +152785,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -152896,8 +152896,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -153485,7 +153485,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -153556,8 +153556,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -153629,8 +153629,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -153784,8 +153784,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -153876,8 +153876,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -154266,8 +154266,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -154332,8 +154332,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -154443,8 +154443,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -155032,7 +155032,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -155103,8 +155103,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -155176,8 +155176,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -155331,8 +155331,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -155423,8 +155423,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -155813,8 +155813,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -155879,8 +155879,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -155990,8 +155990,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -156579,7 +156579,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -156650,8 +156650,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -156723,8 +156723,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -156878,8 +156878,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -156970,8 +156970,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -157360,8 +157360,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -157426,8 +157426,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -157537,8 +157537,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -158126,7 +158126,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -158197,8 +158197,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -158270,8 +158270,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -158425,8 +158425,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -158517,8 +158517,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -158907,8 +158907,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -158973,8 +158973,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -159084,8 +159084,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -159673,7 +159673,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -159744,8 +159744,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -159817,8 +159817,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -159972,8 +159972,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -160064,8 +160064,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -160454,8 +160454,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -160520,8 +160520,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -160631,8 +160631,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -161220,7 +161220,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -161291,8 +161291,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -161364,8 +161364,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -161519,8 +161519,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -161611,8 +161611,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -162001,8 +162001,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -162067,8 +162067,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -162178,8 +162178,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -162767,7 +162767,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -162838,8 +162838,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -162911,8 +162911,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -163066,8 +163066,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -163158,8 +163158,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -163548,8 +163548,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -163614,8 +163614,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -163725,8 +163725,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -164314,7 +164314,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -164385,8 +164385,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -164458,8 +164458,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -164613,8 +164613,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -164705,8 +164705,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -165095,8 +165095,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -165161,8 +165161,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -165272,8 +165272,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -165861,7 +165861,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -165932,8 +165932,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -166005,8 +166005,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -166160,8 +166160,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -166252,8 +166252,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -166642,8 +166642,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -166708,8 +166708,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -166819,8 +166819,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -167408,7 +167408,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -167479,8 +167479,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -167552,8 +167552,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -167707,8 +167707,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -167799,8 +167799,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -168189,8 +168189,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -168255,8 +168255,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -168366,8 +168366,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -168955,7 +168955,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -169026,8 +169026,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -169099,8 +169099,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -169254,8 +169254,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -169346,8 +169346,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -169736,8 +169736,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -169802,8 +169802,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -169913,8 +169913,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -170502,7 +170502,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -170573,8 +170573,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -170646,8 +170646,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -170801,8 +170801,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -170893,8 +170893,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -171283,8 +171283,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -171349,8 +171349,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -171460,8 +171460,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -172049,7 +172049,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -172120,8 +172120,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -172193,8 +172193,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -172348,8 +172348,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -172440,8 +172440,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -172830,8 +172830,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -172896,8 +172896,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -173007,8 +173007,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -173596,7 +173596,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -173667,8 +173667,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -173740,8 +173740,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -173895,8 +173895,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -173987,8 +173987,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -174377,8 +174377,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -174443,8 +174443,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -174554,8 +174554,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -175143,7 +175143,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -175214,8 +175214,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -175287,8 +175287,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -175442,8 +175442,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -175534,8 +175534,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -175924,8 +175924,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -175990,8 +175990,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -176101,8 +176101,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -176690,7 +176690,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -176761,8 +176761,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -176834,8 +176834,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -176989,8 +176989,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -177081,8 +177081,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -177471,8 +177471,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -177537,8 +177537,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -177648,8 +177648,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -178237,7 +178237,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -178308,8 +178308,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -178381,8 +178381,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -178536,8 +178536,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -178628,8 +178628,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -179018,8 +179018,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -179084,8 +179084,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -179195,8 +179195,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -179784,7 +179784,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -179855,8 +179855,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -179928,8 +179928,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -180083,8 +180083,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -180175,8 +180175,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -180565,8 +180565,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -180631,8 +180631,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -180742,8 +180742,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -181331,7 +181331,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -181402,8 +181402,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -181475,8 +181475,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -181630,8 +181630,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -181722,8 +181722,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -182112,8 +182112,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -182178,8 +182178,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -182289,8 +182289,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -182878,7 +182878,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -182949,8 +182949,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -183022,8 +183022,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -183177,8 +183177,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -183269,8 +183269,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -183659,8 +183659,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -183725,8 +183725,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -183836,8 +183836,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -184425,7 +184425,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -184496,8 +184496,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -184569,8 +184569,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -184724,8 +184724,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -184816,8 +184816,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -185206,8 +185206,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -185272,8 +185272,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -185383,8 +185383,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -185972,7 +185972,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -186043,8 +186043,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -186116,8 +186116,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -186271,8 +186271,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -186363,8 +186363,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -186753,8 +186753,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -186819,8 +186819,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -186930,8 +186930,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -187519,7 +187519,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -187590,8 +187590,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -187663,8 +187663,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -187818,8 +187818,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -187910,8 +187910,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -188300,8 +188300,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -188366,8 +188366,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -188477,8 +188477,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -189066,7 +189066,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -189137,8 +189137,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -189210,8 +189210,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -189365,8 +189365,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -189457,8 +189457,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -189847,8 +189847,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -189913,8 +189913,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -190024,8 +190024,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -190613,7 +190613,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -190684,8 +190684,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -190757,8 +190757,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -190912,8 +190912,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -191004,8 +191004,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -191394,8 +191394,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -191460,8 +191460,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -191571,8 +191571,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -192160,7 +192160,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -192231,8 +192231,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -192304,8 +192304,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -192459,8 +192459,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -192551,8 +192551,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -192941,8 +192941,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -193007,8 +193007,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -193118,8 +193118,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -193707,7 +193707,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -193778,8 +193778,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -193851,8 +193851,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -194006,8 +194006,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -194098,8 +194098,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -194488,8 +194488,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -194554,8 +194554,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -194665,8 +194665,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -195254,7 +195254,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -195325,8 +195325,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -195398,8 +195398,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -195553,8 +195553,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -195645,8 +195645,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -196035,8 +196035,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -196101,8 +196101,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -196212,8 +196212,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -196801,7 +196801,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -196872,8 +196872,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -196945,8 +196945,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -197100,8 +197100,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -197192,8 +197192,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -197582,8 +197582,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -197648,8 +197648,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -197759,8 +197759,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -198348,7 +198348,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -198419,8 +198419,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -198492,8 +198492,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -198647,8 +198647,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -198739,8 +198739,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -199129,8 +199129,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -199195,8 +199195,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -199306,8 +199306,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -199895,7 +199895,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -199966,8 +199966,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -200039,8 +200039,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -200194,8 +200194,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -200286,8 +200286,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -200676,8 +200676,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -200742,8 +200742,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -200853,8 +200853,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -201442,7 +201442,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -201513,8 +201513,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -201586,8 +201586,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -201741,8 +201741,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -201833,8 +201833,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -202223,8 +202223,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -202289,8 +202289,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -202400,8 +202400,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -202989,7 +202989,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -203060,8 +203060,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -203133,8 +203133,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -203288,8 +203288,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -203380,8 +203380,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -203770,8 +203770,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -203836,8 +203836,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -203947,8 +203947,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -204536,7 +204536,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -204607,8 +204607,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -204680,8 +204680,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -204835,8 +204835,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -204927,8 +204927,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -205317,8 +205317,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -205383,8 +205383,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -205494,8 +205494,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -206083,7 +206083,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -206154,8 +206154,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -206227,8 +206227,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -206382,8 +206382,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -206474,8 +206474,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -206864,8 +206864,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -206930,8 +206930,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -207041,8 +207041,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -207630,7 +207630,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -207701,8 +207701,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -207774,8 +207774,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -207929,8 +207929,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -208021,8 +208021,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -208411,8 +208411,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -208477,8 +208477,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -208588,8 +208588,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -209177,7 +209177,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -209248,8 +209248,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -209321,8 +209321,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -209476,8 +209476,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -209568,8 +209568,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -209958,8 +209958,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -210024,8 +210024,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -210135,8 +210135,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -210724,7 +210724,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -210795,8 +210795,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -210868,8 +210868,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -211023,8 +211023,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -211115,8 +211115,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -211505,8 +211505,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -211571,8 +211571,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -211682,8 +211682,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -212271,7 +212271,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -212342,8 +212342,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -212415,8 +212415,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -212570,8 +212570,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -212662,8 +212662,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -213052,8 +213052,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -213118,8 +213118,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -213229,8 +213229,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -213818,7 +213818,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -213889,8 +213889,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -213962,8 +213962,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -214117,8 +214117,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -214209,8 +214209,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -214599,8 +214599,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -214665,8 +214665,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -214776,8 +214776,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -215365,7 +215365,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -215436,8 +215436,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -215509,8 +215509,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -215664,8 +215664,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -215756,8 +215756,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -216146,8 +216146,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -216212,8 +216212,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -216323,8 +216323,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -216912,7 +216912,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -216983,8 +216983,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -217056,8 +217056,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -217211,8 +217211,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -217303,8 +217303,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -217693,8 +217693,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -217759,8 +217759,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -217870,8 +217870,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -218459,7 +218459,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -218530,8 +218530,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -218603,8 +218603,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -218758,8 +218758,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -218850,8 +218850,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -219240,8 +219240,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -219306,8 +219306,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -219417,8 +219417,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -220006,7 +220006,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -220077,8 +220077,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -220150,8 +220150,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -220305,8 +220305,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -220397,8 +220397,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -220787,8 +220787,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -220853,8 +220853,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -220964,8 +220964,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -221553,7 +221553,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -221624,8 +221624,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -221697,8 +221697,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -221852,8 +221852,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -221944,8 +221944,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -222334,8 +222334,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -222400,8 +222400,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -222511,8 +222511,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -223100,7 +223100,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -223171,8 +223171,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -223244,8 +223244,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -223399,8 +223399,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -223491,8 +223491,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -223881,8 +223881,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -223947,8 +223947,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -224058,8 +224058,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -224647,7 +224647,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -224718,8 +224718,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -224791,8 +224791,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -224946,8 +224946,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -225038,8 +225038,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -225428,8 +225428,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -225494,8 +225494,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -225605,8 +225605,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -226194,7 +226194,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -226265,8 +226265,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -226338,8 +226338,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -226493,8 +226493,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -226585,8 +226585,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -226975,8 +226975,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -227041,8 +227041,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -227152,8 +227152,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -227741,7 +227741,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -227812,8 +227812,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -227885,8 +227885,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -228040,8 +228040,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -228132,8 +228132,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -228522,8 +228522,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -228588,8 +228588,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -228699,8 +228699,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -229288,7 +229288,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -229359,8 +229359,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -229432,8 +229432,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -229587,8 +229587,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -229679,8 +229679,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -230069,8 +230069,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -230135,8 +230135,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -230246,8 +230246,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -230835,7 +230835,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -230906,8 +230906,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -230979,8 +230979,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -231134,8 +231134,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -231226,8 +231226,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -231616,8 +231616,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -231682,8 +231682,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -231793,8 +231793,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -232382,7 +232382,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -232453,8 +232453,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -232526,8 +232526,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -232681,8 +232681,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -232773,8 +232773,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -233163,8 +233163,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -233229,8 +233229,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -233340,8 +233340,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -233929,7 +233929,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -234000,8 +234000,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -234073,8 +234073,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -234228,8 +234228,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -234320,8 +234320,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -234710,8 +234710,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -234776,8 +234776,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -234887,8 +234887,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -235476,7 +235476,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -235547,8 +235547,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -235620,8 +235620,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -235775,8 +235775,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -235867,8 +235867,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -236257,8 +236257,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -236323,8 +236323,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -236434,8 +236434,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -237023,7 +237023,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -237094,8 +237094,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -237167,8 +237167,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -237322,8 +237322,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -237414,8 +237414,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -237804,8 +237804,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -237870,8 +237870,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -237981,8 +237981,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -238570,7 +238570,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -238641,8 +238641,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -238714,8 +238714,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -238869,8 +238869,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -238961,8 +238961,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -239351,8 +239351,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -239417,8 +239417,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -239528,8 +239528,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -240117,7 +240117,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -240188,8 +240188,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -240261,8 +240261,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -240416,8 +240416,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -240508,8 +240508,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -240898,8 +240898,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -240964,8 +240964,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -241075,8 +241075,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -241664,7 +241664,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -241735,8 +241735,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -241808,8 +241808,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -241963,8 +241963,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -242055,8 +242055,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -242445,8 +242445,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -242511,8 +242511,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -242622,8 +242622,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -243211,7 +243211,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -243282,8 +243282,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -243355,8 +243355,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -243510,8 +243510,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -243602,8 +243602,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -243992,8 +243992,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -244058,8 +244058,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -244169,8 +244169,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -244758,7 +244758,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -244829,8 +244829,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -244902,8 +244902,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -245057,8 +245057,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -245149,8 +245149,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -245539,8 +245539,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -245605,8 +245605,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -245716,8 +245716,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -246305,7 +246305,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -246376,8 +246376,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -246449,8 +246449,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -246604,8 +246604,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -246696,8 +246696,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -247086,8 +247086,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -247152,8 +247152,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -247263,8 +247263,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -247852,7 +247852,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -247923,8 +247923,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -247996,8 +247996,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -248151,8 +248151,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -248243,8 +248243,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -248633,8 +248633,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -248699,8 +248699,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -248810,8 +248810,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -249399,7 +249399,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -249470,8 +249470,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -249543,8 +249543,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -249698,8 +249698,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -249790,8 +249790,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -250180,8 +250180,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -250246,8 +250246,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -250357,8 +250357,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -250946,7 +250946,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -251017,8 +251017,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -251090,8 +251090,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -251245,8 +251245,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -251337,8 +251337,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -251727,8 +251727,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -251793,8 +251793,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -251904,8 +251904,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -252493,7 +252493,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -252564,8 +252564,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -252637,8 +252637,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -252792,8 +252792,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -252884,8 +252884,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -253274,8 +253274,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -253340,8 +253340,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -253451,8 +253451,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -254040,7 +254040,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -254111,8 +254111,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -254184,8 +254184,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -254339,8 +254339,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -254431,8 +254431,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -254821,8 +254821,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -254887,8 +254887,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -254998,8 +254998,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -255587,7 +255587,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -255658,8 +255658,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -255731,8 +255731,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -255886,8 +255886,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -255978,8 +255978,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -256368,8 +256368,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -256434,8 +256434,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -256545,8 +256545,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -257134,7 +257134,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -257205,8 +257205,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -257278,8 +257278,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -257433,8 +257433,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -257525,8 +257525,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -257915,8 +257915,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -257981,8 +257981,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -258092,8 +258092,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -258681,7 +258681,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -258752,8 +258752,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -258825,8 +258825,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -258980,8 +258980,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -259072,8 +259072,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -259462,8 +259462,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -259528,8 +259528,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -259639,8 +259639,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -260228,7 +260228,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -260299,8 +260299,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -260372,8 +260372,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -260527,8 +260527,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -260619,8 +260619,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -261009,8 +261009,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -261075,8 +261075,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -261186,8 +261186,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -261775,7 +261775,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -261846,8 +261846,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -261919,8 +261919,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -262074,8 +262074,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -262166,8 +262166,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -262556,8 +262556,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -262622,8 +262622,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -262733,8 +262733,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -263322,7 +263322,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -263393,8 +263393,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -263466,8 +263466,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -263621,8 +263621,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -263713,8 +263713,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -264103,8 +264103,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -264169,8 +264169,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -264280,8 +264280,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -264869,7 +264869,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -264940,8 +264940,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -265013,8 +265013,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -265168,8 +265168,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -265260,8 +265260,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -265650,8 +265650,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -265716,8 +265716,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -265827,8 +265827,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -266416,7 +266416,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -266487,8 +266487,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -266560,8 +266560,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -266715,8 +266715,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -266807,8 +266807,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -267197,8 +267197,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -267263,8 +267263,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -267374,8 +267374,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -267963,7 +267963,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -268034,8 +268034,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -268107,8 +268107,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -268262,8 +268262,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -268354,8 +268354,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -268744,8 +268744,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -268810,8 +268810,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -268921,8 +268921,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -269510,7 +269510,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -269581,8 +269581,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -269654,8 +269654,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -269809,8 +269809,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -269901,8 +269901,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -270291,8 +270291,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -270357,8 +270357,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -270468,8 +270468,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -271057,7 +271057,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -271128,8 +271128,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -271201,8 +271201,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -271356,8 +271356,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -271448,8 +271448,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -271838,8 +271838,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -271904,8 +271904,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -272015,8 +272015,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -272604,7 +272604,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -272675,8 +272675,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -272748,8 +272748,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -272903,8 +272903,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -272995,8 +272995,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -273385,8 +273385,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -273451,8 +273451,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -273562,8 +273562,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -274151,7 +274151,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -274222,8 +274222,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -274295,8 +274295,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -274450,8 +274450,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -274542,8 +274542,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -274932,8 +274932,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -274998,8 +274998,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -275109,8 +275109,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -275698,7 +275698,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -275769,8 +275769,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -275842,8 +275842,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -275997,8 +275997,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -276089,8 +276089,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -276479,8 +276479,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -276545,8 +276545,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -276656,8 +276656,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -277245,7 +277245,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -277316,8 +277316,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -277389,8 +277389,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -277544,8 +277544,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -277636,8 +277636,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -278026,8 +278026,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -278092,8 +278092,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -278203,8 +278203,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -278792,7 +278792,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -278863,8 +278863,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -278936,8 +278936,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -279091,8 +279091,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -279183,8 +279183,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -279573,8 +279573,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -279639,8 +279639,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -279750,8 +279750,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -280339,7 +280339,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -280410,8 +280410,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -280483,8 +280483,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -280638,8 +280638,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -280730,8 +280730,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -281120,8 +281120,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -281186,8 +281186,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -281297,8 +281297,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -281886,7 +281886,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -281957,8 +281957,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -282030,8 +282030,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -282185,8 +282185,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -282277,8 +282277,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -282667,8 +282667,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -282733,8 +282733,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -282844,8 +282844,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -283433,7 +283433,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -283504,8 +283504,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -283577,8 +283577,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -283732,8 +283732,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -283824,8 +283824,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -284214,8 +284214,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -284280,8 +284280,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -284391,8 +284391,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -284980,7 +284980,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -285051,8 +285051,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -285124,8 +285124,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -285279,8 +285279,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -285371,8 +285371,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -285761,8 +285761,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -285827,8 +285827,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -285938,8 +285938,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -286527,7 +286527,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -286598,8 +286598,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -286671,8 +286671,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -286826,8 +286826,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -286918,8 +286918,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -287308,8 +287308,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -287374,8 +287374,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -287485,8 +287485,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -288074,7 +288074,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -288145,8 +288145,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -288218,8 +288218,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -288373,8 +288373,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -288465,8 +288465,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -288855,8 +288855,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -288921,8 +288921,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -289032,8 +289032,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -289621,7 +289621,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -289692,8 +289692,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -289765,8 +289765,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -289920,8 +289920,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -290012,8 +290012,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -290402,8 +290402,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -290468,8 +290468,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -290579,8 +290579,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -291168,7 +291168,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -291239,8 +291239,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -291312,8 +291312,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -291467,8 +291467,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -291559,8 +291559,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -291949,8 +291949,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -292015,8 +292015,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -292126,8 +292126,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -292715,7 +292715,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -292786,8 +292786,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -292859,8 +292859,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -293014,8 +293014,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -293106,8 +293106,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -293496,8 +293496,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -293562,8 +293562,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -293673,8 +293673,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -294262,7 +294262,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -294333,8 +294333,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -294406,8 +294406,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -294561,8 +294561,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -294653,8 +294653,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -295043,8 +295043,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -295109,8 +295109,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -295220,8 +295220,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -295809,7 +295809,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -295880,8 +295880,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -295953,8 +295953,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -296108,8 +296108,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -296200,8 +296200,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -296590,8 +296590,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -296656,8 +296656,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -296767,8 +296767,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -297356,7 +297356,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -297427,8 +297427,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -297500,8 +297500,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -297655,8 +297655,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -297747,8 +297747,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -298137,8 +298137,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -298203,8 +298203,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -298314,8 +298314,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -298903,7 +298903,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -298974,8 +298974,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -299047,8 +299047,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -299202,8 +299202,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -299294,8 +299294,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -299684,8 +299684,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -299750,8 +299750,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -299861,8 +299861,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -300450,7 +300450,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -300521,8 +300521,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -300594,8 +300594,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -300749,8 +300749,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -300841,8 +300841,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -301231,8 +301231,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -301297,8 +301297,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -301408,8 +301408,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -301997,7 +301997,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -302068,8 +302068,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -302141,8 +302141,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -302296,8 +302296,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -302388,8 +302388,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -302778,8 +302778,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -302844,8 +302844,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -302955,8 +302955,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -303544,7 +303544,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -303615,8 +303615,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -303688,8 +303688,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -303843,8 +303843,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -303935,8 +303935,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -304325,8 +304325,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -304391,8 +304391,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -304502,8 +304502,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -305091,7 +305091,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -305162,8 +305162,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -305235,8 +305235,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -305390,8 +305390,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -305482,8 +305482,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -305872,8 +305872,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -305938,8 +305938,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -306049,8 +306049,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -306638,7 +306638,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -306709,8 +306709,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -306782,8 +306782,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -306937,8 +306937,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -307029,8 +307029,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -307419,8 +307419,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -307485,8 +307485,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -307596,8 +307596,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -308185,7 +308185,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -308256,8 +308256,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -308329,8 +308329,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -308484,8 +308484,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -308576,8 +308576,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -308966,8 +308966,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -309032,8 +309032,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -309143,8 +309143,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -309732,7 +309732,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -309803,8 +309803,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -309876,8 +309876,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -310031,8 +310031,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -310123,8 +310123,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -310513,8 +310513,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -310579,8 +310579,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -310690,8 +310690,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -311279,7 +311279,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -311350,8 +311350,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -311423,8 +311423,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -311578,8 +311578,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -311670,8 +311670,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -312060,8 +312060,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -312126,8 +312126,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -312237,8 +312237,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -312826,7 +312826,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -312897,8 +312897,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -312970,8 +312970,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -313125,8 +313125,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -313217,8 +313217,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -313607,8 +313607,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -313673,8 +313673,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -313784,8 +313784,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -314373,7 +314373,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -314444,8 +314444,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -314517,8 +314517,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -314672,8 +314672,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -314764,8 +314764,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -315154,8 +315154,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -315220,8 +315220,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -315331,8 +315331,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -315920,7 +315920,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -315991,8 +315991,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -316064,8 +316064,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -316219,8 +316219,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -316311,8 +316311,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -316701,8 +316701,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -316767,8 +316767,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -316878,8 +316878,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -317467,7 +317467,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -317538,8 +317538,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -317611,8 +317611,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -317766,8 +317766,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -317858,8 +317858,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -318248,8 +318248,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -318314,8 +318314,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -318425,8 +318425,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -319014,7 +319014,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -319085,8 +319085,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -319158,8 +319158,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -319313,8 +319313,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -319405,8 +319405,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -319795,8 +319795,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -319861,8 +319861,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -319972,8 +319972,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -320561,7 +320561,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -320632,8 +320632,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -320705,8 +320705,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -320860,8 +320860,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -320952,8 +320952,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -321342,8 +321342,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -321408,8 +321408,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -321519,8 +321519,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -322108,7 +322108,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -322179,8 +322179,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -322252,8 +322252,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -322407,8 +322407,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -322499,8 +322499,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -322889,8 +322889,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -322955,8 +322955,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -323066,8 +323066,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -323655,7 +323655,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -323726,8 +323726,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -323799,8 +323799,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -323954,8 +323954,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -324046,8 +324046,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -324436,8 +324436,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -324502,8 +324502,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -324613,8 +324613,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -325202,7 +325202,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -325273,8 +325273,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -325346,8 +325346,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -325501,8 +325501,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -325593,8 +325593,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -325983,8 +325983,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -326049,8 +326049,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -326160,8 +326160,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -326749,7 +326749,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -326820,8 +326820,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -326893,8 +326893,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -327048,8 +327048,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -327140,8 +327140,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -327530,8 +327530,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -327596,8 +327596,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -327707,8 +327707,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -328296,7 +328296,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -328367,8 +328367,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -328440,8 +328440,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -328595,8 +328595,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -328687,8 +328687,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -329077,8 +329077,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -329143,8 +329143,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -329254,8 +329254,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -329843,7 +329843,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -329914,8 +329914,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -329987,8 +329987,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -330142,8 +330142,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -330234,8 +330234,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -330624,8 +330624,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -330690,8 +330690,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -330801,8 +330801,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -331390,7 +331390,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -331461,8 +331461,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -331534,8 +331534,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -331689,8 +331689,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -331781,8 +331781,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -332171,8 +332171,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -332237,8 +332237,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -332348,8 +332348,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -332937,7 +332937,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -333008,8 +333008,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -333081,8 +333081,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -333236,8 +333236,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -333328,8 +333328,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -333718,8 +333718,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -333784,8 +333784,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -333895,8 +333895,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -334484,7 +334484,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -334555,8 +334555,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -334628,8 +334628,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -334783,8 +334783,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -334875,8 +334875,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -335265,8 +335265,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -335331,8 +335331,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -335442,8 +335442,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -336031,7 +336031,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -336102,8 +336102,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -336175,8 +336175,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -336330,8 +336330,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -336422,8 +336422,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -336812,8 +336812,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -336878,8 +336878,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -336989,8 +336989,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -337578,7 +337578,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -337649,8 +337649,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -337722,8 +337722,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -337877,8 +337877,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -337969,8 +337969,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -338359,8 +338359,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -338425,8 +338425,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -338536,8 +338536,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -339125,7 +339125,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -339196,8 +339196,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -339269,8 +339269,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -339424,8 +339424,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -339516,8 +339516,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -339906,8 +339906,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -339972,8 +339972,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -340083,8 +340083,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -340672,7 +340672,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -340743,8 +340743,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -340816,8 +340816,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -340971,8 +340971,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -341063,8 +341063,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -341453,8 +341453,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -341519,8 +341519,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -341630,8 +341630,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -342219,7 +342219,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -342290,8 +342290,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -342363,8 +342363,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -342518,8 +342518,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -342610,8 +342610,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -343000,8 +343000,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -343066,8 +343066,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -343177,8 +343177,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -343766,7 +343766,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -343837,8 +343837,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -343910,8 +343910,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -344065,8 +344065,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -344157,8 +344157,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -344547,8 +344547,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -344613,8 +344613,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -344724,8 +344724,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -345313,7 +345313,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -345384,8 +345384,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -345457,8 +345457,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -345612,8 +345612,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -345704,8 +345704,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -346094,8 +346094,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -346160,8 +346160,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -346271,8 +346271,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -346860,7 +346860,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -346931,8 +346931,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -347004,8 +347004,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -347159,8 +347159,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -347251,8 +347251,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -347641,8 +347641,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -347707,8 +347707,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -347818,8 +347818,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -348407,7 +348407,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -348478,8 +348478,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -348551,8 +348551,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -348706,8 +348706,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -348798,8 +348798,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -349188,8 +349188,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -349254,8 +349254,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -349365,8 +349365,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -349954,7 +349954,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -350025,8 +350025,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -350098,8 +350098,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -350253,8 +350253,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -350345,8 +350345,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -350735,8 +350735,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -350801,8 +350801,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -350912,8 +350912,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -351501,7 +351501,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -351572,8 +351572,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -351645,8 +351645,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -351800,8 +351800,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -351892,8 +351892,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -352282,8 +352282,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -352348,8 +352348,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -352459,8 +352459,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -353048,7 +353048,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -353119,8 +353119,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -353192,8 +353192,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -353347,8 +353347,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -353439,8 +353439,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -353829,8 +353829,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -353895,8 +353895,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -354006,8 +354006,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -354595,7 +354595,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -354666,8 +354666,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -354739,8 +354739,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -354894,8 +354894,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -354986,8 +354986,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -355376,8 +355376,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -355442,8 +355442,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -355553,8 +355553,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -356142,7 +356142,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -356213,8 +356213,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -356286,8 +356286,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -356441,8 +356441,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -356533,8 +356533,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -356923,8 +356923,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -356989,8 +356989,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -357100,8 +357100,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -357689,7 +357689,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -357760,8 +357760,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -357833,8 +357833,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -357988,8 +357988,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -358080,8 +358080,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -358470,8 +358470,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -358536,8 +358536,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -358647,8 +358647,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -359236,7 +359236,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -359307,8 +359307,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -359380,8 +359380,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -359535,8 +359535,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -359627,8 +359627,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -360017,8 +360017,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -360083,8 +360083,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -360194,8 +360194,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -360783,7 +360783,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -360854,8 +360854,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -360927,8 +360927,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -361082,8 +361082,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -361174,8 +361174,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -361564,8 +361564,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -361630,8 +361630,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -361741,8 +361741,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -362330,7 +362330,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -362401,8 +362401,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -362474,8 +362474,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -362629,8 +362629,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -362721,8 +362721,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -363111,8 +363111,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -363177,8 +363177,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -363288,8 +363288,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -363877,7 +363877,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -363948,8 +363948,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -364021,8 +364021,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -364176,8 +364176,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -364268,8 +364268,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -364658,8 +364658,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -364724,8 +364724,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -364835,8 +364835,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -365424,7 +365424,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -365495,8 +365495,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -365568,8 +365568,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -365723,8 +365723,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -365815,8 +365815,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -366205,8 +366205,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -366271,8 +366271,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -366382,8 +366382,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -366971,7 +366971,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -367042,8 +367042,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -367115,8 +367115,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -367270,8 +367270,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -367362,8 +367362,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -367752,8 +367752,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -367818,8 +367818,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -367929,8 +367929,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -368518,7 +368518,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -368589,8 +368589,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -368662,8 +368662,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -368817,8 +368817,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -368909,8 +368909,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -369299,8 +369299,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -369365,8 +369365,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -369476,8 +369476,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -370065,7 +370065,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -370136,8 +370136,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -370209,8 +370209,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -370364,8 +370364,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -370456,8 +370456,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -370846,8 +370846,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -370912,8 +370912,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -371023,8 +371023,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -371612,7 +371612,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -371683,8 +371683,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -371756,8 +371756,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -371911,8 +371911,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -372003,8 +372003,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -372393,8 +372393,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -372459,8 +372459,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -372570,8 +372570,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -373159,7 +373159,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -373230,8 +373230,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -373303,8 +373303,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -373458,8 +373458,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -373550,8 +373550,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -373940,8 +373940,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -374006,8 +374006,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -374117,8 +374117,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -374706,7 +374706,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -374777,8 +374777,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -374850,8 +374850,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -375005,8 +375005,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -375097,8 +375097,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -375487,8 +375487,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -375553,8 +375553,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -375664,8 +375664,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -376253,7 +376253,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -376324,8 +376324,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -376397,8 +376397,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -376552,8 +376552,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -376644,8 +376644,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -377034,8 +377034,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -377100,8 +377100,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -377211,8 +377211,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -377800,7 +377800,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -377871,8 +377871,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -377944,8 +377944,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -378099,8 +378099,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -378191,8 +378191,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -378581,8 +378581,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -378647,8 +378647,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -378758,8 +378758,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -379347,7 +379347,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -379418,8 +379418,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -379491,8 +379491,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -379646,8 +379646,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -379738,8 +379738,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -380128,8 +380128,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -380194,8 +380194,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -380305,8 +380305,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -380894,7 +380894,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -380965,8 +380965,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -381038,8 +381038,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -381193,8 +381193,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -381285,8 +381285,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -381675,8 +381675,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -381741,8 +381741,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -381852,8 +381852,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -382441,7 +382441,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -382512,8 +382512,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -382585,8 +382585,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -382740,8 +382740,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -382832,8 +382832,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -383222,8 +383222,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -383288,8 +383288,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -383399,8 +383399,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -383988,7 +383988,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -384059,8 +384059,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -384132,8 +384132,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -384287,8 +384287,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -384379,8 +384379,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -384769,8 +384769,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -384835,8 +384835,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -384946,8 +384946,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -385535,7 +385535,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -385606,8 +385606,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -385679,8 +385679,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -385834,8 +385834,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -385926,8 +385926,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -386316,8 +386316,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -386382,8 +386382,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -386493,8 +386493,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -387082,7 +387082,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -387153,8 +387153,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -387226,8 +387226,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -387381,8 +387381,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -387473,8 +387473,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -387863,8 +387863,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -387929,8 +387929,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -388040,8 +388040,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -388629,7 +388629,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -388700,8 +388700,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -388773,8 +388773,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -388928,8 +388928,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -389020,8 +389020,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -389410,8 +389410,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -389476,8 +389476,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -389587,8 +389587,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -390176,7 +390176,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -390247,8 +390247,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -390320,8 +390320,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -390475,8 +390475,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -390567,8 +390567,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -390957,8 +390957,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -391023,8 +391023,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -391134,8 +391134,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -391723,7 +391723,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -391794,8 +391794,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -391867,8 +391867,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -392022,8 +392022,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -392114,8 +392114,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -392504,8 +392504,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -392570,8 +392570,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -392681,8 +392681,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -393270,7 +393270,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -393341,8 +393341,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -393414,8 +393414,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -393569,8 +393569,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -393661,8 +393661,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -394051,8 +394051,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -394117,8 +394117,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -394228,8 +394228,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -394817,7 +394817,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -394888,8 +394888,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -394961,8 +394961,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -395116,8 +395116,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -395208,8 +395208,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -395598,8 +395598,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -395664,8 +395664,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -395775,8 +395775,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -396364,7 +396364,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -396435,8 +396435,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -396508,8 +396508,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -396663,8 +396663,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -396755,8 +396755,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -397145,8 +397145,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -397211,8 +397211,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -397322,8 +397322,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -397911,7 +397911,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -397982,8 +397982,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -398055,8 +398055,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -398210,8 +398210,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -398302,8 +398302,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -398692,8 +398692,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -398758,8 +398758,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -398869,8 +398869,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -399458,7 +399458,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -399529,8 +399529,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -399602,8 +399602,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -399757,8 +399757,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -399849,8 +399849,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -400239,8 +400239,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -400305,8 +400305,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -400416,8 +400416,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -401005,7 +401005,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -401076,8 +401076,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -401149,8 +401149,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -401304,8 +401304,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -401396,8 +401396,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -401786,8 +401786,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -401852,8 +401852,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -401963,8 +401963,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -402552,7 +402552,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -402623,8 +402623,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -402696,8 +402696,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -402851,8 +402851,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -402943,8 +402943,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -403333,8 +403333,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -403399,8 +403399,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -403510,8 +403510,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -404099,7 +404099,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -404170,8 +404170,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -404243,8 +404243,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -404398,8 +404398,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -404490,8 +404490,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -404880,8 +404880,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -404946,8 +404946,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -405057,8 +405057,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -405646,7 +405646,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -405717,8 +405717,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -405790,8 +405790,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -405945,8 +405945,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -406037,8 +406037,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -406427,8 +406427,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -406493,8 +406493,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -406604,8 +406604,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -407193,7 +407193,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -407264,8 +407264,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -407337,8 +407337,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -407492,8 +407492,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -407584,8 +407584,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -407974,8 +407974,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -408040,8 +408040,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -408151,8 +408151,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -408740,7 +408740,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -408811,8 +408811,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -408884,8 +408884,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -409039,8 +409039,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -409131,8 +409131,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -409521,8 +409521,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -409587,8 +409587,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -409698,8 +409698,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -410287,7 +410287,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -410358,8 +410358,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -410431,8 +410431,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -410586,8 +410586,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -410678,8 +410678,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -411068,8 +411068,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -411134,8 +411134,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -411245,8 +411245,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -411834,7 +411834,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -411905,8 +411905,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -411978,8 +411978,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -412133,8 +412133,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -412225,8 +412225,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -412615,8 +412615,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -412681,8 +412681,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -412792,8 +412792,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -413381,7 +413381,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -413452,8 +413452,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -413525,8 +413525,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -413680,8 +413680,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -413772,8 +413772,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -414162,8 +414162,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -414228,8 +414228,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -414339,8 +414339,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -414928,7 +414928,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -414999,8 +414999,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -415072,8 +415072,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -415227,8 +415227,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -415319,8 +415319,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -415709,8 +415709,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -415775,8 +415775,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -415886,8 +415886,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -416475,7 +416475,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -416546,8 +416546,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -416619,8 +416619,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -416774,8 +416774,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -416866,8 +416866,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -417256,8 +417256,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -417322,8 +417322,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -417433,8 +417433,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -418022,7 +418022,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -418093,8 +418093,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -418166,8 +418166,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -418321,8 +418321,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -418413,8 +418413,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -418803,8 +418803,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -418869,8 +418869,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -418980,8 +418980,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -419569,7 +419569,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -419640,8 +419640,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -419713,8 +419713,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -419868,8 +419868,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -419960,8 +419960,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -420350,8 +420350,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -420416,8 +420416,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -420527,8 +420527,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -421116,7 +421116,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -421187,8 +421187,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -421260,8 +421260,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -421415,8 +421415,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -421507,8 +421507,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -421897,8 +421897,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -421963,8 +421963,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -422074,8 +422074,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -422663,7 +422663,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -422734,8 +422734,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -422807,8 +422807,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -422962,8 +422962,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -423054,8 +423054,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -423444,8 +423444,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -423510,8 +423510,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -423621,8 +423621,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -424210,7 +424210,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -424281,8 +424281,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -424354,8 +424354,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -424509,8 +424509,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -424601,8 +424601,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -424991,8 +424991,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -425057,8 +425057,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -425168,8 +425168,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -425757,7 +425757,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -425828,8 +425828,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -425901,8 +425901,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -426056,8 +426056,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -426148,8 +426148,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -426538,8 +426538,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -426604,8 +426604,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -426715,8 +426715,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -427304,7 +427304,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -427375,8 +427375,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -427448,8 +427448,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -427603,8 +427603,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -427695,8 +427695,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -428085,8 +428085,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -428151,8 +428151,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -428262,8 +428262,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -428851,7 +428851,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -428922,8 +428922,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -428995,8 +428995,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -429150,8 +429150,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -429242,8 +429242,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -429632,8 +429632,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -429698,8 +429698,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -429809,8 +429809,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -430398,7 +430398,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -430469,8 +430469,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -430542,8 +430542,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -430697,8 +430697,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -430789,8 +430789,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -431179,8 +431179,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -431245,8 +431245,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -431356,8 +431356,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -431945,7 +431945,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -432016,8 +432016,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -432089,8 +432089,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -432244,8 +432244,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -432336,8 +432336,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -432726,8 +432726,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -432792,8 +432792,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -432903,8 +432903,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -433492,7 +433492,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -433563,8 +433563,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -433636,8 +433636,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -433791,8 +433791,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -433883,8 +433883,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -434273,8 +434273,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -434339,8 +434339,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -434450,8 +434450,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -435039,7 +435039,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -435110,8 +435110,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -435183,8 +435183,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -435338,8 +435338,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -435430,8 +435430,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -435820,8 +435820,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -435886,8 +435886,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -435997,8 +435997,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -436586,7 +436586,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -436657,8 +436657,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -436730,8 +436730,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -436885,8 +436885,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -436977,8 +436977,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -437367,8 +437367,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -437433,8 +437433,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -437544,8 +437544,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -438133,7 +438133,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -438204,8 +438204,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -438277,8 +438277,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -438432,8 +438432,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -438524,8 +438524,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -438914,8 +438914,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -438980,8 +438980,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -439091,8 +439091,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -439680,7 +439680,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -439751,8 +439751,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -439824,8 +439824,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -439979,8 +439979,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -440071,8 +440071,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -440461,8 +440461,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -440527,8 +440527,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -440638,8 +440638,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -441227,7 +441227,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -441298,8 +441298,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -441371,8 +441371,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -441526,8 +441526,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -441618,8 +441618,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -442008,8 +442008,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -442074,8 +442074,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -442185,8 +442185,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -442774,7 +442774,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -442845,8 +442845,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -442918,8 +442918,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -443073,8 +443073,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -443165,8 +443165,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -443555,8 +443555,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -443621,8 +443621,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -443732,8 +443732,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -444321,7 +444321,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -444392,8 +444392,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -444465,8 +444465,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -444620,8 +444620,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -444712,8 +444712,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -445102,8 +445102,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -445168,8 +445168,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -445279,8 +445279,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -445868,7 +445868,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -445939,8 +445939,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -446012,8 +446012,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -446167,8 +446167,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -446259,8 +446259,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -446649,8 +446649,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -446715,8 +446715,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -446826,8 +446826,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -447415,7 +447415,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -447486,8 +447486,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -447559,8 +447559,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -447714,8 +447714,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -447806,8 +447806,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -448196,8 +448196,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -448262,8 +448262,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -448373,8 +448373,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -448962,7 +448962,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -449033,8 +449033,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -449106,8 +449106,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -449261,8 +449261,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -449353,8 +449353,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -449743,8 +449743,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -449809,8 +449809,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -449920,8 +449920,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -450509,7 +450509,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -450580,8 +450580,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -450653,8 +450653,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -450808,8 +450808,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -450900,8 +450900,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -451290,8 +451290,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -451356,8 +451356,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -451467,8 +451467,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -452056,7 +452056,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -452127,8 +452127,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -452200,8 +452200,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -452355,8 +452355,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -452447,8 +452447,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -452837,8 +452837,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -452903,8 +452903,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -453014,8 +453014,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -453603,7 +453603,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -453674,8 +453674,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -453747,8 +453747,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -453902,8 +453902,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -453994,8 +453994,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -454384,8 +454384,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -454450,8 +454450,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -454561,8 +454561,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -455150,7 +455150,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -455221,8 +455221,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -455294,8 +455294,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -455449,8 +455449,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -455541,8 +455541,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -455931,8 +455931,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -455997,8 +455997,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -456108,8 +456108,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -456697,7 +456697,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -456768,8 +456768,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -456841,8 +456841,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -456996,8 +456996,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -457088,8 +457088,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -457478,8 +457478,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -457544,8 +457544,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -457655,8 +457655,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -458244,7 +458244,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -458315,8 +458315,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -458388,8 +458388,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -458543,8 +458543,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -458635,8 +458635,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -459025,8 +459025,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -459091,8 +459091,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -459202,8 +459202,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -459791,7 +459791,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -459862,8 +459862,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -459935,8 +459935,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -460090,8 +460090,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -460182,8 +460182,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -460572,8 +460572,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -460638,8 +460638,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -460749,8 +460749,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -461338,7 +461338,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -461409,8 +461409,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -461482,8 +461482,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -461637,8 +461637,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -461729,8 +461729,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -462119,8 +462119,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -462185,8 +462185,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -462296,8 +462296,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -462885,7 +462885,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -462956,8 +462956,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -463029,8 +463029,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -463184,8 +463184,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -463276,8 +463276,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -463666,8 +463666,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -463732,8 +463732,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -463843,8 +463843,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -464432,7 +464432,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -464503,8 +464503,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -464576,8 +464576,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -464731,8 +464731,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -464823,8 +464823,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -465213,8 +465213,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -465279,8 +465279,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -465390,8 +465390,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -465979,7 +465979,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -466050,8 +466050,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -466123,8 +466123,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -466278,8 +466278,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -466370,8 +466370,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -466760,8 +466760,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -466826,8 +466826,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -466937,8 +466937,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -467526,7 +467526,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -467597,8 +467597,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -467670,8 +467670,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -467825,8 +467825,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -467917,8 +467917,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -468307,8 +468307,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -468373,8 +468373,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -468484,8 +468484,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -469073,7 +469073,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -469144,8 +469144,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -469217,8 +469217,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -469372,8 +469372,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -469464,8 +469464,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -469854,8 +469854,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -469920,8 +469920,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -470031,8 +470031,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -470620,7 +470620,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -470691,8 +470691,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -470764,8 +470764,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -470919,8 +470919,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -471011,8 +471011,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -471401,8 +471401,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -471467,8 +471467,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -471578,8 +471578,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -472167,7 +472167,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -472238,8 +472238,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -472311,8 +472311,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -472466,8 +472466,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -472558,8 +472558,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -472948,8 +472948,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -473014,8 +473014,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -473125,8 +473125,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -473714,7 +473714,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -473785,8 +473785,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -473858,8 +473858,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -474013,8 +474013,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -474105,8 +474105,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -474495,8 +474495,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -474561,8 +474561,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -474672,8 +474672,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -475261,7 +475261,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -475332,8 +475332,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -475405,8 +475405,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -475560,8 +475560,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -475652,8 +475652,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -476042,8 +476042,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -476108,8 +476108,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -476219,8 +476219,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -476808,7 +476808,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -476879,8 +476879,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -476952,8 +476952,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -477107,8 +477107,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -477199,8 +477199,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -477589,8 +477589,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -477655,8 +477655,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -477766,8 +477766,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -478355,7 +478355,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -478426,8 +478426,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -478499,8 +478499,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -478654,8 +478654,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -478746,8 +478746,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -479136,8 +479136,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -479202,8 +479202,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -479313,8 +479313,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -479902,7 +479902,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -479973,8 +479973,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -480046,8 +480046,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -480201,8 +480201,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -480293,8 +480293,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -480683,8 +480683,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -480749,8 +480749,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -480860,8 +480860,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -481449,7 +481449,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -481520,8 +481520,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -481593,8 +481593,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -481748,8 +481748,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -481840,8 +481840,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -482230,8 +482230,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -482296,8 +482296,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -482407,8 +482407,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -482996,7 +482996,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -483067,8 +483067,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -483140,8 +483140,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -483295,8 +483295,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -483387,8 +483387,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -483777,8 +483777,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -483843,8 +483843,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -483954,8 +483954,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -484543,7 +484543,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -484614,8 +484614,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -484687,8 +484687,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -484842,8 +484842,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -484934,8 +484934,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -485324,8 +485324,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -485390,8 +485390,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -485501,8 +485501,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -486090,7 +486090,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -486161,8 +486161,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -486234,8 +486234,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -486389,8 +486389,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -486481,8 +486481,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -486871,8 +486871,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -486937,8 +486937,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -487048,8 +487048,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -487637,7 +487637,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -487708,8 +487708,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -487781,8 +487781,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -487936,8 +487936,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -488028,8 +488028,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -488418,8 +488418,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -488484,8 +488484,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -488595,8 +488595,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -489184,7 +489184,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -489255,8 +489255,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -489328,8 +489328,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -489483,8 +489483,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -489575,8 +489575,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -489965,8 +489965,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -490031,8 +490031,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -490142,8 +490142,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -490731,7 +490731,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -490802,8 +490802,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -490875,8 +490875,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -491030,8 +491030,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -491122,8 +491122,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -491512,8 +491512,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -491578,8 +491578,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -491689,8 +491689,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -492278,7 +492278,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -492349,8 +492349,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -492422,8 +492422,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -492577,8 +492577,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -492669,8 +492669,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -493059,8 +493059,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -493125,8 +493125,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -493236,8 +493236,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -493825,7 +493825,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -493896,8 +493896,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -493969,8 +493969,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -494124,8 +494124,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -494216,8 +494216,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -494606,8 +494606,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -494672,8 +494672,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -494783,8 +494783,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -495372,7 +495372,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -495443,8 +495443,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -495516,8 +495516,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -495671,8 +495671,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -495763,8 +495763,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -496153,8 +496153,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -496219,8 +496219,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -496330,8 +496330,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -496919,7 +496919,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -496990,8 +496990,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -497063,8 +497063,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -497218,8 +497218,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -497310,8 +497310,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -497700,8 +497700,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -497766,8 +497766,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -497877,8 +497877,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -498466,7 +498466,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -498537,8 +498537,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -498610,8 +498610,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -498765,8 +498765,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -498857,8 +498857,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -499247,8 +499247,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -499313,8 +499313,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -499424,8 +499424,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -500013,7 +500013,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -500084,8 +500084,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -500157,8 +500157,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -500312,8 +500312,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -500404,8 +500404,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -500794,8 +500794,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -500860,8 +500860,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -500971,8 +500971,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -501560,7 +501560,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -501631,8 +501631,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -501704,8 +501704,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -501859,8 +501859,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -501951,8 +501951,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -502341,8 +502341,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -502407,8 +502407,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -502518,8 +502518,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -503107,7 +503107,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -503178,8 +503178,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -503251,8 +503251,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -503406,8 +503406,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -503498,8 +503498,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -503888,8 +503888,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -503954,8 +503954,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -504065,8 +504065,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -504654,7 +504654,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -504725,8 +504725,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -504798,8 +504798,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -504953,8 +504953,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -505045,8 +505045,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -505435,8 +505435,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -505501,8 +505501,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -505612,8 +505612,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -506201,7 +506201,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -506272,8 +506272,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -506345,8 +506345,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -506500,8 +506500,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -506592,8 +506592,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -506982,8 +506982,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -507048,8 +507048,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -507159,8 +507159,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -507748,7 +507748,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -507819,8 +507819,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -507892,8 +507892,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -508047,8 +508047,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -508139,8 +508139,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -508529,8 +508529,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -508595,8 +508595,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -508706,8 +508706,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -509295,7 +509295,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -509366,8 +509366,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -509439,8 +509439,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -509594,8 +509594,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -509686,8 +509686,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -510076,8 +510076,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -510142,8 +510142,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -510253,8 +510253,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -510842,7 +510842,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -510913,8 +510913,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -510986,8 +510986,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -511141,8 +511141,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -511233,8 +511233,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -511623,8 +511623,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -511689,8 +511689,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -511800,8 +511800,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -512389,7 +512389,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -512460,8 +512460,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -512533,8 +512533,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -512688,8 +512688,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -512780,8 +512780,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -513170,8 +513170,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -513236,8 +513236,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -513347,8 +513347,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -513936,7 +513936,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -514007,8 +514007,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -514080,8 +514080,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -514235,8 +514235,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -514327,8 +514327,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -514717,8 +514717,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -514783,8 +514783,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -514894,8 +514894,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -515483,7 +515483,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -515554,8 +515554,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -515627,8 +515627,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -515782,8 +515782,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -515874,8 +515874,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -516264,8 +516264,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -516330,8 +516330,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -516441,8 +516441,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -517030,7 +517030,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -517101,8 +517101,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -517174,8 +517174,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -517329,8 +517329,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -517421,8 +517421,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -517811,8 +517811,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -517877,8 +517877,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -517988,8 +517988,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -518577,7 +518577,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -518648,8 +518648,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -518721,8 +518721,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -518876,8 +518876,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -518968,8 +518968,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -519358,8 +519358,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -519424,8 +519424,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -519535,8 +519535,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -520124,7 +520124,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -520195,8 +520195,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -520268,8 +520268,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -520423,8 +520423,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -520515,8 +520515,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -520905,8 +520905,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -520971,8 +520971,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -521082,8 +521082,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -521671,7 +521671,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -521742,8 +521742,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -521815,8 +521815,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -521970,8 +521970,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -522062,8 +522062,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -522452,8 +522452,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -522518,8 +522518,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -522629,8 +522629,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -523218,7 +523218,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -523289,8 +523289,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -523362,8 +523362,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -523517,8 +523517,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -523609,8 +523609,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -523999,8 +523999,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -524065,8 +524065,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -524176,8 +524176,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -524765,7 +524765,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -524836,8 +524836,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -524909,8 +524909,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -525064,8 +525064,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -525156,8 +525156,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -525546,8 +525546,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -525612,8 +525612,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -525723,8 +525723,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -526312,7 +526312,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -526383,8 +526383,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -526456,8 +526456,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -526611,8 +526611,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -526703,8 +526703,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -527093,8 +527093,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -527159,8 +527159,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -527270,8 +527270,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -527859,7 +527859,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -527930,8 +527930,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -528003,8 +528003,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -528158,8 +528158,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -528250,8 +528250,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -528640,8 +528640,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -528706,8 +528706,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -528817,8 +528817,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -529406,7 +529406,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -529477,8 +529477,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -529550,8 +529550,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -529705,8 +529705,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -529797,8 +529797,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -530187,8 +530187,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -530253,8 +530253,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -530364,8 +530364,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -530953,7 +530953,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -531024,8 +531024,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -531097,8 +531097,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -531252,8 +531252,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -531344,8 +531344,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -531734,8 +531734,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -531800,8 +531800,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -531911,8 +531911,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -532500,7 +532500,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -532571,8 +532571,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -532644,8 +532644,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -532799,8 +532799,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -532891,8 +532891,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -533281,8 +533281,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -533347,8 +533347,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -533458,8 +533458,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -534047,7 +534047,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -534118,8 +534118,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -534191,8 +534191,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -534346,8 +534346,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -534438,8 +534438,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -534828,8 +534828,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -534894,8 +534894,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -535005,8 +535005,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -535594,7 +535594,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -535665,8 +535665,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -535738,8 +535738,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -535893,8 +535893,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -535985,8 +535985,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -536375,8 +536375,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -536441,8 +536441,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -536552,8 +536552,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -537141,7 +537141,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -537212,8 +537212,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -537285,8 +537285,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -537440,8 +537440,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -537532,8 +537532,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -537922,8 +537922,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -537988,8 +537988,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -538099,8 +538099,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -538688,7 +538688,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -538759,8 +538759,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -538832,8 +538832,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -538987,8 +538987,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -539079,8 +539079,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -539469,8 +539469,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -539535,8 +539535,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -539646,8 +539646,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -540235,7 +540235,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -540306,8 +540306,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -540379,8 +540379,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -540534,8 +540534,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -540626,8 +540626,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -541016,8 +541016,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -541082,8 +541082,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -541193,8 +541193,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -541782,7 +541782,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -541853,8 +541853,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -541926,8 +541926,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -542081,8 +542081,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -542173,8 +542173,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -542563,8 +542563,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -542629,8 +542629,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -542740,8 +542740,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -543329,7 +543329,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -543400,8 +543400,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -543473,8 +543473,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -543628,8 +543628,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -543720,8 +543720,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -544110,8 +544110,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -544176,8 +544176,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -544287,8 +544287,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -544876,7 +544876,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -544947,8 +544947,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -545020,8 +545020,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -545175,8 +545175,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -545267,8 +545267,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -545657,8 +545657,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -545723,8 +545723,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -545834,8 +545834,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -546423,7 +546423,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -546494,8 +546494,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -546567,8 +546567,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -546722,8 +546722,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -546814,8 +546814,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -547204,8 +547204,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -547270,8 +547270,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -547381,8 +547381,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -547970,7 +547970,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -548041,8 +548041,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -548114,8 +548114,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -548269,8 +548269,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -548361,8 +548361,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -548751,8 +548751,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -548817,8 +548817,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -548928,8 +548928,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -549517,7 +549517,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -549588,8 +549588,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -549661,8 +549661,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -549816,8 +549816,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -549908,8 +549908,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -550298,8 +550298,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -550364,8 +550364,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -550475,8 +550475,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -551064,7 +551064,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -551135,8 +551135,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -551208,8 +551208,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -551363,8 +551363,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -551455,8 +551455,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -551845,8 +551845,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -551911,8 +551911,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -552022,8 +552022,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -552611,7 +552611,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -552682,8 +552682,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -552755,8 +552755,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -552910,8 +552910,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -553002,8 +553002,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -553392,8 +553392,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -553458,8 +553458,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -553569,8 +553569,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -554158,7 +554158,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -554229,8 +554229,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -554302,8 +554302,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -554457,8 +554457,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -554549,8 +554549,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -554939,8 +554939,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -555005,8 +555005,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -555116,8 +555116,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -555705,7 +555705,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -555776,8 +555776,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -555849,8 +555849,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -556004,8 +556004,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -556096,8 +556096,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -556486,8 +556486,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -556552,8 +556552,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -556663,8 +556663,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -557252,7 +557252,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -557323,8 +557323,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -557396,8 +557396,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -557551,8 +557551,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -557643,8 +557643,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -558033,8 +558033,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -558099,8 +558099,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -558210,8 +558210,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -558799,7 +558799,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -558870,8 +558870,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -558943,8 +558943,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -559098,8 +559098,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -559190,8 +559190,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -559580,8 +559580,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -559646,8 +559646,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -559757,8 +559757,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -560346,7 +560346,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -560417,8 +560417,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -560490,8 +560490,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -560645,8 +560645,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -560737,8 +560737,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -561127,8 +561127,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -561193,8 +561193,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -561304,8 +561304,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -561893,7 +561893,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -561964,8 +561964,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -562037,8 +562037,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -562192,8 +562192,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -562284,8 +562284,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -562674,8 +562674,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -562740,8 +562740,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -562851,8 +562851,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -563440,7 +563440,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -563511,8 +563511,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -563584,8 +563584,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -563739,8 +563739,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -563831,8 +563831,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -564221,8 +564221,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -564287,8 +564287,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -564398,8 +564398,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -564987,7 +564987,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -565058,8 +565058,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -565131,8 +565131,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -565286,8 +565286,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -565378,8 +565378,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -565768,8 +565768,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -565834,8 +565834,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -565945,8 +565945,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -566534,7 +566534,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -566605,8 +566605,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -566678,8 +566678,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -566833,8 +566833,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -566925,8 +566925,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -567315,8 +567315,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -567381,8 +567381,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -567492,8 +567492,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -568081,7 +568081,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -568152,8 +568152,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -568225,8 +568225,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -568380,8 +568380,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -568472,8 +568472,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -568862,8 +568862,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -568928,8 +568928,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -569039,8 +569039,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -569628,7 +569628,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -569699,8 +569699,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -569772,8 +569772,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -569927,8 +569927,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -570019,8 +570019,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -570409,8 +570409,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -570475,8 +570475,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -570586,8 +570586,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -571175,7 +571175,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -571246,8 +571246,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -571319,8 +571319,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -571474,8 +571474,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -571566,8 +571566,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -571956,8 +571956,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -572022,8 +572022,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -572133,8 +572133,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -572722,7 +572722,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -572793,8 +572793,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -572866,8 +572866,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -573021,8 +573021,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -573113,8 +573113,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -573503,8 +573503,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -573569,8 +573569,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -573680,8 +573680,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -574269,7 +574269,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -574340,8 +574340,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -574413,8 +574413,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -574568,8 +574568,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -574660,8 +574660,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -575050,8 +575050,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -575116,8 +575116,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -575227,8 +575227,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -575816,7 +575816,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -575887,8 +575887,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -575960,8 +575960,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -576115,8 +576115,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -576207,8 +576207,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -576597,8 +576597,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -576663,8 +576663,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -576774,8 +576774,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -577363,7 +577363,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -577434,8 +577434,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -577507,8 +577507,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -577662,8 +577662,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -577754,8 +577754,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -578144,8 +578144,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -578210,8 +578210,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -578321,8 +578321,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -578910,7 +578910,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -578981,8 +578981,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -579054,8 +579054,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -579209,8 +579209,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -579301,8 +579301,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -579691,8 +579691,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -579757,8 +579757,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -579868,8 +579868,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -580457,7 +580457,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -580528,8 +580528,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -580601,8 +580601,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -580756,8 +580756,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -580848,8 +580848,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -581238,8 +581238,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -581304,8 +581304,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -581415,8 +581415,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -582004,7 +582004,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -582075,8 +582075,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -582148,8 +582148,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -582303,8 +582303,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -582395,8 +582395,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -582785,8 +582785,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -582851,8 +582851,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -582962,8 +582962,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -583551,7 +583551,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -583622,8 +583622,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -583695,8 +583695,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -583850,8 +583850,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -583942,8 +583942,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -584332,8 +584332,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -584398,8 +584398,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -584509,8 +584509,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, @@ -585098,7 +585098,7 @@ {}, { "techniqueID": "T1059", - "score": 71, + "score": 72, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml" }, { @@ -585169,8 +585169,8 @@ {}, { "techniqueID": "T1562.001", - "score": 37, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 38, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, {}, @@ -585242,8 +585242,8 @@ {}, { "techniqueID": "T1222.001", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml" }, {}, {}, @@ -585397,8 +585397,8 @@ {}, { "techniqueID": "T1222", - "score": 12, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml" }, {}, {}, @@ -585489,8 +585489,8 @@ }, { "techniqueID": "T1562", - "score": 92, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml" + "score": 94, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/experimental/ssa___disable_defender_antivirus_registry.yml" }, {}, { @@ -585879,8 +585879,8 @@ {}, { "techniqueID": "T1070", - "score": 27, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" + "score": 29, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml" }, {}, { @@ -585945,8 +585945,8 @@ {}, { "techniqueID": "T1059.003", - "score": 7, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" + "score": 8, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml" }, {}, {}, @@ -586056,8 +586056,8 @@ {}, { "techniqueID": "T1070.004", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml" }, {}, {}, From 8b93c999040755ff29746e64a8d3ac677806880f Mon Sep 17 00:00:00 2001 From: P4T12ICK Date: Wed, 2 Feb 2022 08:48:26 +0100 Subject: [PATCH 2/3] trouble shooting --- .../ssa___hiding_files_and_directories_with_attrib_exe.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml index e3fa20820f..c23cfbac84 100644 --- a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml @@ -76,3 +76,4 @@ tags: - _time risk_score: 72 security_domain: endpoint + From 634d28efe39b132386d9205fcf05781460c8c45e Mon Sep 17 00:00:00 2001 From: P4T12ICK Date: Wed, 2 Feb 2022 10:45:37 +0100 Subject: [PATCH 3/3] trouble shooting --- .../ssa___hiding_files_and_directories_with_attrib_exe.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml index c23cfbac84..9444d3e8d4 100644 --- a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml @@ -16,7 +16,7 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%+h%") AND process_name="attrib.exe" | + cmd_line IS NOT NULL AND match_regex(cmd_line, /\+h/)=true AND process_name="attrib.exe" | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name",